Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, permits an unauthenticated attacker with network access to a vulnerable instance to compromise the service through an exposed TCP interface. The vulnerability is classified as difficult to exploit but, once successfully leveraged, allows full takeover of the Coherence service, potentially granting an attacker the ability to read, modify or delete data, execute arbitrary code, and disrupt service availability. This weakness aligns with improper access control or authentication issues, as indicated by the lack of required credentials for remote interaction.

Affected Systems

Affected vendors and products include Oracle Corporation’s Oracle Coherence. The specific versions impacted are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability applies to the core component of these releases, which can be identified by the corresponding common platform enumeration strings.

Risk and Exploitability

The CVSS v3.1 score of 8.1 reflects severe confidentiality, integrity, and availability compromises. The EPSS score of less than 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be network‑based over TCP, with no user interaction or elevated privileges required, meaning that remote exploitation is feasible from any network location that can reach the vulnerable port. Proper remediation requires applying the official patch or update as provided by Oracle and tightening network exposure of the service.

Generated by OpenCVE AI on July 30, 2026 at 15:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence security patch for versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 as detailed in the Oracle CPU Jul 2026 advisory.
  • Restrict network access to the Coherence service, for example by configuring firewalls or VPNs to limit connections to trusted hosts or administrative networks.
  • If the exposed TCP port is not required for business operations, disable it or block the port entirely to eliminate the remote attack surface.
  • Enable or enforce proper authentication mechanisms on the Coherence service to ensure that only authorized clients can connect.

Generated by OpenCVE AI on July 30, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote TCP Vulnerability Allows Full Takeover of Oracle Coherence

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Remote TCP Vulnerability Allows Full Takeover of Oracle Coherence
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:50:59.995Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60277

cve-icon Vulnrichment

Updated: 2026-07-23T17:50:53.184Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T15:15:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function