Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence contains a flaw in its core component that allows a high‑privileged attacker who has local access to the host where Coherence runs to read or obtain all data stored or accessible through the Coherence cluster. The vulnerability is classified as a CWE‑284 Improper Access Control weakness; it does not provide denial of service or code execution but delivers full confidentiality compromise. Because the attack requires local privileged access, it is not a network‑based vulnerability, and the attacker can gain read‑only visibility into all Coherence data once the flaw is exploited, potentially exposing sensitive business information.

Affected Systems

Affected systems are Oracle Coherence version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The product is supplied by Oracle Corporation and is part of the Oracle Fusion Middleware stack.

Risk and Exploitability

With a CVSS 3.1 base score of 6.0 the vulnerability is rated moderate. The EPSS score is below 1 %, indicating a very low current exploitation probability, and it is not listed in CISA’s KEV database. The likely attack vector is local and requires high‑privileged infrastructure access; no network exposure is needed. When the flaw is exploited, an attacker obtains full read‑only visibility into all Coherence data, potentially leaking sensitive information. The CVSS vector indicates a scope change, meaning that the impact could cascade to other Oracle products that rely on the compromised Coherence instance.

Generated by OpenCVE AI on August 2, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Oracle CPU update for Oracle Coherence to eliminate the vulnerability.
  • Restrict local administrative privileges on all servers hosting Oracle Coherence; enforce least‑privilege principles for Coherence accounts.
  • Disable unnecessary local shell or credential access to Coherence nodes and monitor for suspicious activity.

Generated by OpenCVE AI on August 2, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Data Access Vulnerability Allowing Unauthorized Confidential Data Exposure

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Data Access Vulnerability Allowing Unauthorized Confidential Data Exposure

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:29:30.606Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60265

cve-icon Vulnrichment

Updated: 2026-07-23T17:29:06.648Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:15:05Z

Weaknesses