Impact
Oracle Coherence, part of Oracle Fusion Middleware, contains a vulnerability that allows an attacker to gain total control of the system without authentication. The flaw can be triggered over a network connection using standard TCP ports, giving the attacker full compromise of confidentiality, integrity, and availability. Successful exploitation can lead to complete takeover of the Coherence service, enabling arbitrary code execution and unrestricted access to data stored or passed through the cluster.
Affected Systems
This issue affects all Oracle Coherence installations in the July 2026 release series, specifically versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All instances of Oracle Fusion Middleware that deploy these Coherence versions are impacted. The vulnerability applies only to the Core component of the product.
Risk and Exploitability
The base CVSS score of 8.1 indicates high severity, with no privileges or user interaction required. The EPSS score of less than 1% shows that a statistical model currently considers exploitation to be unlikely but not impossible. This vulnerability is not listed in the CISA KEV catalog, so no publicly known active exploitation has been reported yet. Attackers would need network access to the Coherence service and must exploit the lack of authentication checks; the ability to compromise a system hinges on reaching the exposed TCP ports.
OpenCVE Enrichment