Executive brief
Oracle Coherence, a distributed data management platform used for high-speed data processing and application scaling, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability over a network to gain full control of the system. This could lead to the theft of sensitive data, disruption of business operations, and total compromise of the affected environment.
Technical details
A vulnerability in the Core component of Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory