Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Coherence, a component of Oracle Fusion Middleware, allows an unauthenticated attacker with network access via TCP to take full control of the application. This easily exploitable vulnerability can result in takeover, compromising confidentiality, integrity, and availability. The weakness is a lack of authentication, mapping to CWE-306.

Affected Systems

Affected products include Oracle Coherence from Oracle Corporation. The impacted releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Risk and Exploitability

The CVSS 3.1 Base Score of 9.8 indicates a critical risk. The EPSS score is below 1 %, suggesting a low probability of exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote TCP connection, unauthenticated, exploiting a core component that permits full compromise.

Generated by OpenCVE AI on August 2, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence patch or newer release that addresses the vulnerability
  • Re‑configure the Coherence service to only listen on trusted interfaces or restrict network access via firewalls
  • Enable logging and monitor for anomalous inbound TCP sessions as an early detection measure

Generated by OpenCVE AI on August 2, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Network Access Exploitation Leading to Full Compromise in Oracle Coherence

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Easily Exploitable Remote Code Execution in Oracle Coherence
Weaknesses CWE-284

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Easily Exploitable Remote Code Execution in Oracle Coherence
Weaknesses CWE-284

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T16:53:29.515Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60296

cve-icon Vulnrichment

Updated: 2026-07-23T18:40:13.616Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function