Impact
The vulnerability enables an unauthenticated remote attacker with network access over TCP to compromise an Oracle Coherence instance, resulting in full takeover of the system. The flaw, classified as CWE‑306 (Missing Authentication), provides complete confidentiality, integrity, and availability impacts as reflected by the high CVSS score. No additional detail is supplied regarding the underlying code path, but the description indicates a flaw that can be triggered without authentication and that can be exploited readily by an attacker.
Affected Systems
Affected vendors include Oracle Corporation with the Oracle Coherence product. The impacted product versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The bug is present in the Core component of Oracle Fusion Middleware and is referenced in the Oracle CPU July 2026 advisory.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical severity. The EPSS score is below 1%, indicating that while exploitation probability is low, a vulnerability of this magnitude can attract targeted attacks. The vulnerability is not listed in the CISA KEV catalog, but its impact and ease of exploitation make it highly relevant for systems in production. The likely attack path involves an unauthenticated TCP connection to the Coherence service, where the vulnerability allows remote code execution or system takeover. No additional prerequisites such as authentication or privileged user are required based on the information provided.
OpenCVE Enrichment