Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, part of Oracle Fusion Middleware, contains a flaw that permits an unauthenticated attacker with network connectivity to a Coherence HTTP endpoint to seize control of the application. The vulnerability can be exploited to bypass authentication and perform arbitrary actions, causing compromise of confidentiality, integrity, and availability. The flaw matches CWE-306: Missing Authentication for Critical Function, and is classified as a high‑severity remote exploitation with the potential for persistent, system‑wide impact once the attacker gains entry.

Affected Systems

Oracle Corporation’s Oracle Coherence product is affected. Supported releases with this flaw include version 12.2.1.4.0 and 14.1.1.0.0. These versions run on a variety of platforms where Coherence provides distributed data caching and messaging capabilities.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 reflects extreme impact and an ease of attack: Network attacker, low access complexity, no privilege or user interaction. EPSS indicates a probability of less than 1 % at the time of the analysis but the flaw’s remote nature and lack of authentication mean any reachable HTTP interface could be abused. The vulnerability is not listed in CISA’s KEV catalog, but that does not reduce its risk. An attacker would target exposed HTTP ports on Coherence nodes, send a crafted request and gain administrative or execution capabilities without requiring credentials.

Generated by OpenCVE AI on August 4, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor’s patch or upgrade to an unaffected Coherence release
  • If a patch is not yet available, restrict external HTTP access to Coherence nodes using firewalls or ACLs
  • Implement additional monitoring for anomalous HTTP traffic and failed authentication attempts

Generated by OpenCVE AI on August 4, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allowing Full Oracle Coherence Takeover

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Coherence

Fri, 24 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:51:52.726Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60278

cve-icon Vulnrichment

Updated: 2026-07-23T17:51:47.712Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function