Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, part of Oracle Fusion Middleware, contains a vulnerability that allows an attacker to gain total control of the system without authentication. The flaw can be triggered over a network connection using standard TCP ports, giving the attacker full compromise of confidentiality, integrity, and availability. Successful exploitation can lead to complete takeover of the Coherence service, enabling arbitrary code execution and unrestricted access to data stored or passed through the cluster.

Affected Systems

This issue affects all Oracle Coherence installations in the July 2026 release series, specifically versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All instances of Oracle Fusion Middleware that deploy these Coherence versions are impacted. The vulnerability applies only to the Core component of the product.

Risk and Exploitability

The base CVSS score of 8.1 indicates high severity, with no privileges or user interaction required. The EPSS score of less than 1% shows that a statistical model currently considers exploitation to be unlikely but not impossible. This vulnerability is not listed in the CISA KEV catalog, so no publicly known active exploitation has been reported yet. Attackers would need network access to the Coherence service and must exploit the lack of authentication checks; the ability to compromise a system hinges on reaching the exposed TCP ports.

Generated by OpenCVE AI on August 4, 2026 at 17:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence patches issued in the July 2026 Critical Patch Update to address the authentication bypass flaw (CWE‑306).
  • Enforce proper access control by configuring firewall rules to restrict inbound TCP traffic to the Coherence service, allowing only trusted IP addresses or VPN endpoints (CWE‑284).
  • Enable mandatory authentication and audit logging for all Coherence connections, and ensure the system requires credentials before allowing remote operations (CWE‑306).

Generated by OpenCVE AI on August 4, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Authentication Bypass Enables System Takeover

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Authentication Bypass Enables System Takeover

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Attack Exploits Oracle Coherence Vulnerability Allowing System Takeover
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Attack Exploits Oracle Coherence Vulnerability Allowing System Takeover
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:30:14.407Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60273

cve-icon Vulnrichment

Updated: 2026-07-23T19:30:09.428Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function