Junglewise Threat Intelligence

CVE-2026-35304: Oracle Coherence authentication bypass in Core component

CVE-2026-35304 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a distributed data management platform used for high-speed data processing and application scaling, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability over a network to gain full control of the system. This could lead to the theft of sensitive data, disruption of business operations, and total compromise of the affected environment.

Technical details

A vulnerability in the Core component of Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats