Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authentication flaw (CWE‑306) that exists in the core component of Oracle Coherence, part of Oracle Fusion Middleware. An unauthenticated attacker who can reach the service over a TCP connection can exploit the flaw to gain full control of the Coherence service. The attacker obtains the same privileges as the service process, enabling arbitrary code execution, sensitive data disclosure, and denial of service. CVSS 3.1 scores it as high severity, with complete confidentiality, integrity, and availability impact.

Affected Systems

Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. No other versions were listed as affected.

Risk and Exploitability

The vulnerability is rated CVSS 9.8 and has an EPSS score of less than 1 %. It is not currently listed in the CISA KEV catalog. The attack vector or special privileges, making exploitation straightforward for any attacker with network access to the target. The combination of high severity, low exploitation the affected product make this a high‑risk vulnerability.

Generated by OpenCVE AI on August 2, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Oracle Coherence as released by Oracle
  • Restrict inbound TCP traffic to the Coherence listening port to trusted hosts via firewall policies
  • Disable or remove the Coherence service if it is not required, or run it in a hardened, isolated network segment

Generated by OpenCVE AI on August 2, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Missing Authentication in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Remote Code Execution via Unauthenticated TCP Access
Weaknesses CWE-287
CWE-98

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Remote Code Execution via Unauthenticated TCP Access
Weaknesses CWE-287
CWE-98

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:06:10.399Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60256

cve-icon Vulnrichment

Updated: 2026-07-23T17:06:01.311Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:15:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function