Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability enables an unauthenticated attacker who can reach the Oracle Coherence service over TLS to create, delete, or modify data, or simply read all protected data. The CVSS v3.1 base score of 9.1 reflects high confidentiality and integrity impacts with no availability change. The attack requires no authentication but demands network access to the Coherence endpoints, meaning that any exposed listener can be targeted.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These are components of Oracle Fusion Middleware used for distributed caching and data storage.

Risk and Exploitability

The EPSS score of less than 1% indicates a low likelihood of widespread exploitation, and the vulnerability is not yet listed in CISA KEV. However, the high CVSS score and the fact that the attack vector is network‑based via TLS mean that an attacker with internet or internal network access to the Coherence cluster can initiate the exploitation. The lack of authentication on the exposed interface represents a classic improper access control flaw, making the risk significant for any organization deploying an exposed Coherence service.

Generated by OpenCVE AI on August 4, 2026 at 04:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the unauthenticated TLS access flaw for all affected Coherence versions
  • Re‑configure the Coherence deployment to disable unnecessary TLS endpoints or enforce strict authentication before allowing access
  • Restrict inbound TLS traffic to the Coherence service to trusted networks or specific IP ranges and enable logging to detect anomalous connection attempts

Generated by OpenCVE AI on August 4, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated TLS Access Enables Unauthorized Data Modification in Oracle Coherence

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated TLS Access Enables Unauthorized Data Modification in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Exploit in Oracle Coherence over TLS
Weaknesses CWE-287

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Exploit in Oracle Coherence over TLS
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:34:55.331Z

Reserved: 2026-07-08T15:51:40.526Z

Link: CVE-2026-60267

cve-icon Vulnrichment

Updated: 2026-07-23T17:32:10.715Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses