Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables an unauthenticated remote attacker with network access over TCP to compromise an Oracle Coherence instance, resulting in full takeover of the system. The flaw, classified as CWE‑306 (Missing Authentication), provides complete confidentiality, integrity, and availability impacts as reflected by the high CVSS score. No additional detail is supplied regarding the underlying code path, but the description indicates a flaw that can be triggered without authentication and that can be exploited readily by an attacker.

Affected Systems

Affected vendors include Oracle Corporation with the Oracle Coherence product. The impacted product versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The bug is present in the Core component of Oracle Fusion Middleware and is referenced in the Oracle CPU July 2026 advisory.

Risk and Exploitability

The CVSS base score of 9.8 indicates a critical severity. The EPSS score is below 1%, indicating that while exploitation probability is low, a vulnerability of this magnitude can attract targeted attacks. The vulnerability is not listed in the CISA KEV catalog, but its impact and ease of exploitation make it highly relevant for systems in production. The likely attack path involves an unauthenticated TCP connection to the Coherence service, where the vulnerability allows remote code execution or system takeover. No additional prerequisites such as authentication or privileged user are required based on the information provided.

Generated by OpenCVE AI on August 4, 2026 at 04:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence patch released in the CPU July 2026 advisory for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0).
  • After installing the patch, restart all Oracle Coherence services to ensure the new code is loaded.
  • Restrict inbound network access to Coherence ports by configuring firewall rules so that only trusted hosts and authenticated users can connect.

Generated by OpenCVE AI on August 4, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via TCP in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via TCP in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:41:10.629Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60246

cve-icon Vulnrichment

Updated: 2026-07-23T15:41:05.994Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function