Junglewise Threat Intelligence

CVE-2026-35306: Oracle Coherence improper access control in Centralized Third Party Jars

CVE-2026-35306 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw in its third-party library components. An unauthorized person can exploit this over the network to gain full access to sensitive business data or modify records without permission. This could lead to significant data breaches and may also compromise other integrated business systems.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in the Centralized Third Party Jars component of Oracle Coherence version 15.1.1.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Due to a scope change (Status: Changed), an exploit can impact not only Coherence but also additional products within the Oracle Fusion Middleware stack. Attackers can achieve complete confidentiality impact, gaining access to all accessible data, and partial integrity impact through unauthorized data manipulation. Users are advised to refer to the Oracle June 2026 Security Alert for patching information.

Affected products

  • Oracle Coherence 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats