Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access over TCP can exploit a flaw in the Core component of Oracle Coherence, allowing unauthorized updates, inserts, deletes and reads of a subset of stored data. The vulnerability is a moderate severity issue (CVSS 5.4) that impacts confidentiality and integrity but has no availability impact.

Affected Systems

Oracle Coherence, part of Oracle Fusion Middleware, is affected in the following releases: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The CVE notes that the flaw resides in the Core component running in these versions.

Risk and Exploitability

The CVSS Base Score of 5.4 indicates moderate severity; the EPSS score of less than 1% signifies a low probability of exploitation in the current threat landscape, and the issue is not listed in CISA’s KEV catalog. Attackers need only basic network connectivity to a Coherence instance and low privilege to exploit the flaw, making the attack vector relatively simple. Applying the vendor patch when it becomes available, restricting TCP access to trusted hosts, and monitoring for unauthorized data modification attempts are the recommended defenses.

Generated by OpenCVE AI on August 4, 2026 at 04:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence patch that includes the fix.
  • Restrict inbound TCP traffic to the Coherence instance to trusted hosts using firewalls or security groups.
  • Enable audit logging for data modification operations and review logs regularly for indications of unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via TCP in Oracle Coherence

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via TCP in Oracle Coherence

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via TCP in Oracle Coherence

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via TCP in Oracle Coherence
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:07:47.271Z

Reserved: 2026-07-08T15:51:40.527Z

Link: CVE-2026-60282

cve-icon Vulnrichment

Updated: 2026-07-23T17:58:33.375Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:05Z

Weaknesses