Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence contains an easily exploitable authorisation flaw that allows an attacker with local access on the host where the service runs to fully compromise the instance. The vulnerability permits privilege escalation that leads to complete takeover, enabling the attacker to read, modify or delete data and disrupt service availability. The weakness is an authorisation failure (CWE-269), exposing the system to confidentiality, integrity and availability breaches.

Affected Systems

The flaw affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, which are deployed as part of Oracle Fusion Middleware. Users running these releases are at risk if the environment is not appropriately hardened.

Risk and Exploitability

The CVSS 3.1 base score of 9.3 (AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates the attack requires local access, no additional privileges, and escalates authority to all system components. The EPSS value of less than 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Anyone able to log on to the host can exploit this flaw and gain full control over the Coherence instance.

Generated by OpenCVE AI on August 4, 2026 at 17:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence patch for the affected releases as released by Oracle.
  • Restrict operating‑system level access to nodes running Coherence, enforcing the principle of least privilege for all local users.
  • Implement network segmentation and continuous monitoring to detect and block suspicious local activity targeting the Coherence service.

Generated by OpenCVE AI on August 4, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Local Authorization Flaw Enables System Takeover

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Local Authorization Flaw Enables System Takeover

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Takeover of Oracle Coherence via Unrestricted Local Access
Weaknesses CWE-284
CWE-862

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Takeover of Oracle Coherence via Unrestricted Local Access
Weaknesses CWE-284
CWE-862

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:39:40.063Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60248

cve-icon Vulnrichment

Updated: 2026-07-23T15:39:34.327Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management