Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Coherence allows an attacker who can reach the service over HTTP to take full control of the application. The flaw is an unauthenticated access issue that permits remote execution, causing total compromise of confidentiality, integrity and availability. The weakness corresponds to improper access control, enabling the attacker to alter or read all protected data and processes.

Affected Systems

Oracle Corporation's Oracle Coherence product, versions 12.2.1.4.0 and 14.1.1.0.0, is affected. The vulnerability exists in the Core component and can be reached by any host that can make HTTP requests to the Coherence service.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity, but the EPSS score of less than 1% suggests a low probability of exploitation at this time. The CVE is not listed in CISA’s KEV catalog. Attacks would likely occur over an exposed HTTP interface without authentication, so network access is the primary requirement. The impact would be a full takeover of the Coherence server.

Generated by OpenCVE AI on August 4, 2026 at 04:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update July 2026 for Oracle Coherence 12.2.1.4.0 and 14.1.1.0.0.
  • If an immediate patch is not feasible, isolate the Coherence service by restricting HTTP access to trusted hosts only.
  • Enable logging and monitor for anomalous HTTP requests to the Coherence endpoints to detect potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle Coherence
Weaknesses CWE-200
CWE-284

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle Coherence
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:40:26.574Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60247

cve-icon Vulnrichment

Updated: 2026-07-23T15:40:16.761Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function