Impact
The vulnerability resides in Oracle Coherence’s core component and allows a low‑privileged user who can log on to the underlying infrastructure to cause unauthorized creation, deletion or modification of critical data. The impact is a compromise of Confidentiality and Integrity of all data accessible through Oracle Coherence, and the scope expands to other Oracle Fusion Middleware components. The weakness is a form of improper access control, enabling an attacker to perform actions beyond the intended privilege level.
Affected Systems
Affected versions are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These releases are listed as vulnerable in Oracle’s July 2026 CPU advisory.
Risk and Exploitability
The CVSS 3.1 base score is 7.2, indicating a medium‑high severity. The EPSS score is below 1%, showing a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires local access with low privileges and human interaction from a user other than the attacker, meaning the attack is difficult and reliant on an insider or attacker with physical or console access. While the attack vector is local, the potential fallout can affect additional products in the hosting environment, raising the overall risk.
OpenCVE Enrichment