Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It is a CWE-200 type weakness where an unauthenticated attacker with network access via TLS can read data stored in the Coherence cluster, granting access to all sensitive information held there. The impact affects confidentiality, reflected in the CVSS 3.1 base score of 5.9 and the C:H vector component.

Affected Systems

Oracle Coherence version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, as identified in Oracle’s July 2026 CPU advisory, are affected. These releases are provided by Oracle Corporation and are used in enterprise in‑memory data grid deployments.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is absent from CISA’s KEV catalogue, indicating that exploitation is currently rare. Successful exploitation requires an attacker to send a crafted TLS packet to an unauthenticated Coherence node; no credentials are needed. The resulting risk is moderate, driven largely by the confidentiality loss and the low exploitation probability.

Generated by OpenCVE AI on August 4, 2026 at 04:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Patch released in the July 2026 CPU advisory
  • Restrict network access to Oracle Coherence nodes to trusted IP ranges or enforce firewall rules
  • Monitor TLS traffic for anomalous requests from unauthorized sources

Generated by OpenCVE AI on August 4, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated TLS Access Enables Confidential Data Disclosure in Oracle Coherence

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated TLS Access Enables Confidential Data Disclosure in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:36:56.339Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60266

cve-icon Vulnrichment

Updated: 2026-07-23T17:36:48.403Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor