Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Coherence’s core component makes it possible for an attacker with low privileges who can reach the service over TCP to compromise the Coherence cluster. The flaw is considered difficult to exploit, but once triggered it allows the attacker to take over the Coherence component, potentially leading to loss of confidentiality, integrity, and availability. Because the vulnerability is in a core component, the impact may actually extend beyond Coherence to other applications that rely on it, changing the affected scope.

Affected Systems

The affected versions are Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, all released under Oracle Corporation’s Fusion Middleware umbrella. No further vendor or product information is provided beyond the Oracle Coherence listing.

Risk and Exploitability

The CVSS 3.1 base score of 8.5 indicates a high‑severity flaw. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the vulnerability is reachable over the network, requires only low privileges, and its exploit can lead to full takeover of the component. Attackers would need access to the internal network or be able to reach the TCP ports that expose Coherence; there is no mention of user interaction or fallback defenses.

Generated by OpenCVE AI on August 4, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence patch released with the CPU July 2026 update to all affected installations
  • Upgrade to a version of Oracle Coherence not listed as vulnerable in the CPU release
  • Restrict TCP access to Coherence ports to trusted hosts only by configuring firewalls or network segmentation

Generated by OpenCVE AI on August 4, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege TCP Attack Enables Coherence Cluster Takeover

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Enables Takeover of Oracle Coherence

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Enables Takeover of Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:37:48.700Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60295

cve-icon Vulnrichment

Updated: 2026-07-23T18:37:26.988Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses