Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a Missing Authentication issue (CWE-306) in the Core component of Oracle Coherence, allowing an unauthenticated attacker who can reach the system over HTTP to fully compromise the Coherence instance. A successful exploit results in a complete takeover, providing the attacker with full control of the system. The flaw leads to simultaneous confidentiality, integrity, and availability impacts, as reflected by the CVSS 3.1 base score of 9.8.

Affected Systems

Oracle Coherence from Oracle Corporation is affected. The versions listed in the CVSS information are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The vulnerability is tied exclusively to the Core component of these releases.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity; the EPSS score of less than 1 % suggests a very low probability of exploitation at the moment, and the vulnerability is not currently listed in the CISA KEV catalog. However, because the flaw is easily exploitable and requires only unauthenticated network access via HTTP, organizations should treat it as a high risk and prioritize remediation. If an attacker gains network access to the exposed HTTP endpoints, the attack can be conducted with minimal effort and without authentication.

Generated by OpenCVE AI on August 2, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update (CPU) released in July 2026 for Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
  • If a patch is not immediately available, block HTTP access to the Coherence endpoints or restrict it to trusted IP ranges using firewall rules.
  • Enable or enforce authentication and proper access controls on the Coherence administrative interfaces to prevent unauthenticated interaction.

Generated by OpenCVE AI on August 2, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Missing Authentication in Oracle Coherence Enables Remote Code Execution

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access Allows Complete System Takeover in Oracle Coherence
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access Allows Complete System Takeover in Oracle Coherence
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:21:31.773Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60259

cve-icon Vulnrichment

Updated: 2026-07-23T17:21:22.871Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:15:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function