Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Coherence, identified as CWE‑306 (Missing Authentication for Critical Function), allows an unauthenticated attacker with network access via HTTP to compromise the application, effectively taking full control of the Coherence instance. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a high confidence that exploitation can lead to confidential data disclosure, integrity violations, and complete availability loss, reflecting a full compromise of the system.

Affected Systems

Affected systems are Oracle Corporation’s Coherence component of Oracle Fusion Middleware. The versions subject to the flaw are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These versions are supported under Oracle’s product lifecycle and are routinely accessed over HTTP interfaces.

Risk and Exploitability

The CVSS score of 9.8 marks the issue as critical, but the EPSS score of less than 1% indicates that current exploitation activity is low despite the severity. Since the vulnerability is listed as not in CISA’s KEV catalog, no known public exploits are currently documented. The likely attack vector is an unauthenticated HTTP request to exposed Coherence endpoints, with no privilege requirement or user interaction needed. If exploited, an attacker gains total control over the affected instance, enabling data exfiltration, tampering, or service disruption.

Generated by OpenCVE AI on August 4, 2026 at 04:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle Coherence update released in the CPU Jul 2026 advisory or upgrade to a non‑affected version
  • If patching cannot be performed immediately, limit network exposure by blocking external HTTP traffic to the Coherence service and allow it only from trusted hosts
  • Disable or remove any HTTP endpoints that are not required for normal business operation

Generated by OpenCVE AI on August 4, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Takeover in Oracle Coherence

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle Coherence via Unauthenticated HTTP Access
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle Coherence via Unauthenticated HTTP Access
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:07:58.724Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60289

cve-icon Vulnrichment

Updated: 2026-07-23T18:07:44.523Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function