Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, part of Oracle Fusion Middleware, has a flaw that permits an unauthenticated attacker to gain full control of the service through HTTP traffic. The vulnerability enables an attacker to compromise confidentiality, integrity, and availability, effectively taking over the Coherence cluster. The flaw is classified under CWE‑306 (Missing Authentication).

Affected Systems

The affected releases are Oracle Coherence 12.2.1.4.0 and 14.1.1.0.0. Based on the description, it is inferred that any deployment using these versions without the latest security update is vulnerable and may allow a remote attacker to compromise the system.

Risk and Exploitability

Based on the description, the likely attack vector is an unauthenticated HTTP request to an exposed Oracle Coherence endpoint. A remote attacker does not need credentials. Though the EPSS score is less than 1%, indicating a very low current exploitation probability, the CVSS base score of 9.8 shows severe impact across confidentiality, integrity, and availability. Because the vulnerability is not listed in the CISA KEV catalog, no publicly known exploits exist yet, but the combination of zero‑authentication and full takeover potential warrants urgent remediation.

Generated by OpenCVE AI on August 4, 2026 at 17:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Determine whether an Oracle Coherence deployment uses version 12.2.1.4.0 or 14.1.1.0.0.
  • Apply the security patch or update released by Oracle for the affected Coherence version as specified in the official advisory.
  • Restrict or remove HTTP access to the Coherence cluster to eliminate the exposed attack surface when a patch cannot be applied immediately.

Generated by OpenCVE AI on August 4, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via HTTP in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via HTTP in Oracle Coherence
Weaknesses CWE-200
CWE-285

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via HTTP in Oracle Coherence
Weaknesses CWE-200
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:59:42.067Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60244

cve-icon Vulnrichment

Updated: 2026-07-23T16:57:27.640Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function