Junglewise Threat Intelligence

CVE-2026-35305: Oracle Coherence improper access control in Centralized Third Party Jars

CVE-2026-35305 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw in its third-party library components. An unauthenticated attacker can exploit this over the network to gain full access to sensitive business data or modify records. Because this component is often integrated with other systems, a successful attack could also compromise additional connected products and services.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in Oracle Coherence version 15.1.1.0.0 within the Centralized Third Party Jars component. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. A successful exploit results in a 'scope change' (SSVC:C), meaning the attacker can impact products beyond Oracle Coherence itself. Impact includes unauthorized read access to all accessible data and unauthorized modification (update, insert, or delete) of a subset of data. Oracle has addressed this in the June 2026 security alert.

Affected products

  • Oracle Coherence 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats