Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, part of Oracle Fusion Middleware, has a vulnerability (CWE‑306: Missing Authentication for Critical Function) that allows an attacker with network access to connect via TCP and perform an unauthenticated takeover of the Coherence service. The flaw grants the attacker full control, enabling modification of data, execution of arbitrary code, and denial of service, affecting confidentiality, integrity, and availability. This issue is reflected in a CVSS v3.1 base score of 9.8, indicating critical severity.

Affected Systems

Vulnerable versions include Oracle Coherence 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These are supported releases and deploy the affected Core component. No additional operating systems or deployment specifics are listed in the advisory.

Risk and Exploitability

The vulnerability arises from missing authentication (CWE‑306), meaning an attacker requires only network connectivity to the exposed Coherence TCP port, with no credentials or local privilege escalation needed. The EPSS score is below 1%, suggesting low observed exploitation frequency, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS score and the nature of the flaw—requiring only network connectivity to the target port—make exploitation technically straightforward. Given the potential impact, the risk remains high for any environment where the Coherence service is reachable from untrusted networks.

Generated by OpenCVE AI on August 2, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence security patch or upgrade to a version released after 15.1.1.0.0 that resolves this issue
  • Limit network exposure by configuring firewalls or security groups to allow inbound Coherence TCP traffic only from trusted hosts or networks
  • Separate the Coherence deployment into a dedicated, isolated network segment and monitor for anomalous connection attempts or unauthorized activity

Generated by OpenCVE AI on August 2, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via TCP in Oracle Coherence
Weaknesses CWE-200
CWE-287

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via TCP in Oracle Coherence
Weaknesses CWE-200
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:43:35.621Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60299

cve-icon Vulnrichment

Updated: 2026-07-23T18:43:30.432Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function