Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the Core component of Oracle Coherence and permits an unauthenticated attacker to exploit the HTTP interface to fully compromise the system. The flaw essentially bypasses authentication, allowing the attacker to take control, thereby exposing confidentiality, integrity and availability of the application. The weakness is consistent with improper check for authorization (CWE-306).

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected; these are the only releases identified as vulnerable by Oracle.

Risk and Exploitability

The CVSS v3.1 score of 9.8 classifies it as critical, while the EPSS score of less than 1% indicates a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack path involves sending specially crafted HTTP requests to an exposed Coherence service from an external network, with no authentication or user interaction required. Because the vulnerability is easily exploitable, an attacker who can reach the service can gain full administrative rights over the application.

Generated by OpenCVE AI on August 2, 2026 at 23:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update for July 2026 that addresses the Core component vulnerability in Oracle Coherence.
  • Limit inbound HTTP traffic to Oracle Coherence to trusted IP ranges or apply firewall rules to block unauthorized access.
  • Enable detailed logging for the Coherence service and monitor for anomalous access patterns, alerting on repeated attempts or successful connections.

Generated by OpenCVE AI on August 2, 2026 at 23:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Full Compromise of Oracle Coherence

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Core Unauthenticated HTTP Remote Compromise
Weaknesses CWE-287

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Core Unauthenticated HTTP Remote Compromise
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:00:06.273Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60286

cve-icon Vulnrichment

Updated: 2026-07-23T17:59:58.954Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:15:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function