Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Coherence allows an unauthenticated attacker with network access via TCP to fully compromise the software. An attacker can send specially crafted data to a vulnerable node and gain control, resulting in a complete takeover of the Coherence cluster. The impact spans confidentiality, integrity and availability, disrupting data and services managed by Coherence.

Affected Systems

Affecting Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, this flaw impacts installations that expose the Coherence ports to the network. Network administrators must verify whether any of these versions are deployed within the organization and ensure that the software is isolated or patched.

Risk and Exploitability

The CVSS v3 high severity risk, with low attack complexity and no privileges required. The EPSS score is less than 1% and it is not listed in the CISA KEV catalog. Nevertheless, the flaw is exploited over the network through a TCP connection, requiring no authentication and affecting the entire system once an attacker can reach the vulnerable endpoint. Prompt remediation is therefore advised.

Generated by OpenCVE AI on August 4, 2026 at 04:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s published patch for CVE-2026-60257 or upgrade to a version that is not affected
  • Configure firewalls or network segmentation to block unauthenticated TCP traffic to Coherence listening ports
  • Set up monitoring for anomalous connection attempts to Coherence nodes and enforce strict authentication if available
  • If a patch is not immediately available, consider disabling external exposure of Coherence services until a fix can be applied

Generated by OpenCVE AI on August 4, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Remote Code Execution in Oracle Coherence

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Remote Code Execution in Oracle Coherence
Weaknesses CWE-284
CWE-502

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Remote Exploit in Oracle Coherence Enables Full Takeover

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Remote Exploit in Oracle Coherence Enables Full Takeover
Weaknesses CWE-284
CWE-502

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:16:17.715Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60257

cve-icon Vulnrichment

Updated: 2026-07-23T17:15:43.067Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function