Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Coherence allows an unauthenticated attacker to send specially crafted TCP packets that are interpreted as commands, leading to takeover of Oracle Coherence. The vulnerability is classified as a high‑impact flaw, with a CVSS 3.1 Base Score of 9.8, indicating that successful exploitation would compromise the confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are commonly deployed as part of Oracle Fusion Middleware in enterprise environments.

Risk and Exploitability

The flaw can be exploited remotely over the network, requiring only TCP connectivity and no authentication. The EPSS score of less than 1% suggests that the likelihood of a real‑world exploit is currently low, but the absence of the vulnerability from the CISA KEV catalog does not mitigate the high potential impact. Attackers would need to construct and transmit malicious packets that exploit the authentication weakness highlighted by CWE‑306.

Generated by OpenCVE AI on August 4, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence security patch released in Oracle CPU July 2026 to address the authentication weakness
  • Restrict TCP access to the Coherence service by configuring firewalls or network ACLs to allow only trusted IP ranges
  • Actively monitor Coherence logs and network traffic for anomalous connection attempts or unexpected command activity

Generated by OpenCVE AI on August 4, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Exploit Enables Takeover of Oracle Coherence

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP
Weaknesses CWE-20
CWE-287

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP
Weaknesses CWE-20
CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:41:55.156Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60306

cve-icon Vulnrichment

Updated: 2026-07-23T18:41:36.775Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function