Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Oracle Coherence Core component permits an unauthenticated attacker with network access over TCP to compromise the system. If successfully exploited, the attacker can take over the Oracle Coherence cluster, leading to loss of confidentiality, integrity, and availability. This behavior is reflected in a CVSS v3.1 Base Score of 9.8, indicating a high severity where the flaw can result in full system takeover.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and are typically used in distributed caching and data grid deployments.

Risk and Exploitability

The CVSS score of 9.8 shows a severe impact, and the EPSS score of less than 1% suggests the likelihood of exploitation at present is low but non‑zero. The vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the exposed TCP interface from any networked host; no authentication or explicit authorization is required. This makes the attack vector straightforward, and if an exploit is deployed, it can lead to a full compromise of the affected Oracle Coherence instance.

Generated by OpenCVE AI on August 4, 2026 at 17:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch or upgrade Oracle Coherence to a version that addresses the improper access control flaw identified as CWE-284
  • Enforce network segmentation and restrict inbound TCP traffic to trusted hosts, ensuring that only authorized services can reach the Coherence cluster—this counters the lack of proper access control
  • Audit and monitor cluster logs for unauthorized access attempts or privilege escalation indicators, which are symptoms of the CWE-284 access control issue

Generated by OpenCVE AI on August 4, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Compromise via TCP in Oracle Coherence Core Component

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote code execution via TCP in Oracle Coherence
Weaknesses CWE-20
CWE-78

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote code execution via TCP in Oracle Coherence
Weaknesses CWE-20
CWE-78

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:07:52.347Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60269

cve-icon Vulnrichment

Updated: 2026-07-23T17:44:37.299Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses