Impact
The vulnerability resides in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It is a CWE-200 type weakness where an unauthenticated attacker with network access via TLS can read data stored in the Coherence cluster, granting access to all sensitive information held there. The impact affects confidentiality, reflected in the CVSS 3.1 base score of 5.9 and the C:H vector component.
Affected Systems
Oracle Coherence version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, as identified in Oracle’s July 2026 CPU advisory, are affected. These releases are provided by Oracle Corporation and are used in enterprise in‑memory data grid deployments.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is absent from CISA’s KEV catalogue, indicating that exploitation is currently rare. Successful exploitation requires an attacker to send a crafted TLS packet to an unauthenticated Coherence node; no credentials are needed. The resulting risk is moderate, driven largely by the confidentiality loss and the low exploitation probability.
OpenCVE Enrichment