Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, part of Oracle Fusion Middleware, contains a flaw (CWE‑306) that permits an unauthenticated attacker with network access via HTTP/2 to compromise the service. The vulnerability is easily exploitable and can result in full takeover of the Coherence instance, potentially leading to loss of confidentiality, integrity, and availability for data and applications relying on that instance. The likely impact, based on the wording of the announcement, includes loss of confidentiality, integrity and availability.

Affected Systems

Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. Any deployment that exposes these versions to the network on HTTP/2 is vulnerable.

Risk and Exploitability

With a CVSS base score of 9.8, the vulnerability is classified as critical. The EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is unauthenticated network access via HTTP/2, requiring only that the attacker can send crafted HTTP/2 frames to the Coherence service. Successful exploitation would allow an attacker to fully control the Coherence instance, and depending on the environment, further compromise could be possible. The weakness is a missing authentication check (CWE-306).

Generated by OpenCVE AI on August 4, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Coherence
  • Block or disable HTTP/2 traffic to Coherence servers until the patch is applied or the service is re‑architected to drop HTTP/2 support
  • Enforce strict authentication and access controls for Coherence endpoints, ensuring that only authorized users can perform privileged operations
  • Monitor system logs for anomalous HTTP/2 traffic patterns that may indicate attempted exploitation

Generated by OpenCVE AI on August 4, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP/2 Exploit Compromises Oracle Coherence Service

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP/2 in Oracle Coherence
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP/2 in Oracle Coherence
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:55:28.803Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60280

cve-icon Vulnrichment

Updated: 2026-07-23T17:55:20.385Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function