Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who can reach Oracle Coherence over the network to bypass authentication entirely and obtain full control of the application. Once compromised, the attacker can modify, delete, or exfiltrate data, and launch further attacks against the surrounding environment. The CVSS 3.1 base score of 9.8 reflects the attacker's ability to execute code, alter data and cause denial of service, with high impacts on confidentiality, integrity, and availability.

Affected Systems

This flaw affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 across all supported releases.

Risk and Exploitability

The risk is high due to the lack of authentication required for exploitation and the potential for complete takeover. The EPSS score of less than 1% indicates current exploitation probability is low, but the severity remains high, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be remote over TCP based on the network access requirement mentioned in the description, allowing direct exploitation via Coherence’s listening endpoints.

Generated by OpenCVE AI on August 4, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch released for the affected Coherence versions as detailed in the Oracle Security Alert
  • Restrict inbound TCP access to Coherence by configuring firewalls or network segmentation so that only trusted hosts can reach the service
  • Monitor logs for suspicious authentication attempts or integration anomalies and verify service behavior after changes

Generated by OpenCVE AI on August 4, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Authentication Bypass in Oracle Coherence

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Authentication Bypass in Oracle Coherence
Weaknesses CWE-284
CWE-287

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote takeover of Oracle Coherence via TCP

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote takeover of Oracle Coherence via TCP
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:22:01.579Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60285

cve-icon Vulnrichment

Updated: 2026-07-23T19:21:50.648Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function