Executive brief
Oracle Coherence, a widely used data grid solution for high-performance applications, contains a critical security flaw. An unauthenticated attacker can remotely take full control of the system over the network. This could lead to the theft of sensitive data, disruption of business operations, and potential compromise of other connected corporate systems.
Technical details
A vulnerability classified as Improper Access Control (CWE-284) exists in the Core component of Oracle Coherence. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a 'scope change' (S:C), meaning the attacker can potentially impact components beyond Oracle Coherence itself. This can lead to a total loss of confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to consult the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory