Impact
CVE‑2026‑60298 is a flaw in the Core component of Oracle Coherence that allows an unauthenticated attacker with network connectivity to the Coherence TCP port to send a crafted packet that bypasses required authentication and establishes full control over the application. The missing or inadequate authentication check is reflected in CWE‑306. Once exploited the attacker can execute arbitrary code, thereby compromising the confidentiality, integrity and availability of the Coherence instance and any data or services it provides.
Affected Systems
The vulnerability affects Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Network endpoints deployed with these versions expose a TCP listener that, according to the CPE data, is commonly used in on‑premises Oracle Fusion Middleware environments.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 marks this as critical, but the EPSS score of less than 1 % indicates a low current exploitation likelihood, and the issue is not listed in CISA’s KEV catalog. The only requirement for exploitation is an attacker that can reach the Coherence TCP port; no user interaction or credentials are needed, making the attack path straightforward and potentially viable in any environment where the port is exposed.
OpenCVE Enrichment