Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker with network access via TCP to fully compromise an Oracle Coherence instance, resulting in a complete system takeover. The impact covers confidentiality, integrity, and availability due to the CVSS vector indicating no requirement for user interaction and a high severity score of 9.8. This weakness is a CWE‑306 missing authentication for critical functions, permitting a remote attacker to gain privileges without authentication.

Affected Systems

The affected product is Oracle Coherence from Oracle Corporation. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable; updates later than these versions are not listed as affected.

Risk and Exploitability

The CVSS base score of 9.8 indicates a critical vulnerability, but the EPSS score of <1% shows that, as of this assessment, the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely over the network without authentication by connecting to the Coherence TCP interfaces, potentially executing arbitrary code and taking over the system.

Generated by OpenCVE AI on August 2, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence patch released by Oracle for versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, as documented in the Oracle CPU July 2026 advisory.
  • Upgrade to a non-affected version of Oracle Coherence if the patch cannot be applied immediately.
  • Restrict network access to Coherence services by configuring firewall rules or network segmentation to block inbound TCP connections from untrusted sources.

Generated by OpenCVE AI on August 2, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution through Missing Authentication in Oracle Coherence

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle Coherence
Weaknesses CWE-284

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle Coherence
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:24:10.853Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60262

cve-icon Vulnrichment

Updated: 2026-07-23T17:24:00.723Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:15:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function