Impact
A local vulnerability in Oracle Coherence allows an unauthenticated attacker who can physically communicate with the host to take full control of the Coherence service. The flaw is easily exploitable and provides complete compromise of confidentiality, integrity, and availability of the impacted instance. Attackers could tamper with cached data, disrupt distributed processing, and potentially pivot to other systems that depend on Coherence.
Affected Systems
Oracle Corporation’s Oracle Coherence product is affected, specifically versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These are the only releases listed as vulnerable in the Oracle security advisory for the July 2026 CPU.
Risk and Exploitability
The CVSS 3.1 score of 8.8 reflects high severity, with full confidentiality, integrity and availability impact. The EPSS score is below 1 %, indicating the expected exploitation rate is very low, and the vulnerability is not listed in CISA’s KEV catalog. The attack path requires physical or local network access to the communication segment on the host running Coherence, enabling an attacker to get unauthenticated control and seize the service.
OpenCVE Enrichment