Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the Core component of Oracle Coherence and allows an attacker with high privileges and network access via HTTP to bypass normal access controls. It can lead to unauthorized reading of confidential data and modifying or deleting entries, thereby compromising data integrity. The issue is evident from the CVSS vector which highlights high confidentiality impact and low integrity impact, confirming the potential for significant data exposure and alteration.

Affected Systems

Affected products are Oracle Corporation's Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All these versions are listed in the advisory as vulnerable and would need to be updated or otherwise secured to mitigate the risk.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity, but the vulnerability is easily exploitable from any network location that can reach the HTTP endpoint, making it a realistic threat. The EPSS score of less than 1% suggests low current exploitation probability, however the vulnerability is not part of the CISA KEV catalog, meaning there is no evidence of widespread attacks yet but the potential remains. Exploit likely requires an attacker who has high privileges on the system or can elevate privileges through the compromised component.

Generated by OpenCVE AI on August 4, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Coherence to a non‑affected version or apply the patch provided in the Oracle CPU Jul 2026 advisory
  • Configure firewall or network segmentation to block HTTP access to Coherence services unless absolutely necessary
  • Limit the privileged user accounts that can access Coherence and enforce least privilege principles

Generated by OpenCVE AI on August 4, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Oracle Coherence HTTP Access Exploit Enables Unauthorized Data Modification

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence HTTP Access Exploit Enables Unauthorized Data Modification

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Attack Enables Unauthorized Access and Data Modification in Oracle Coherence

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Attack Enables Unauthorized Access and Data Modification in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:46:10.980Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60270

cve-icon Vulnrichment

Updated: 2026-07-23T17:46:04.863Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:05Z

Weaknesses