Junglewise Threat Intelligence

CVE-2026-35308: Oracle Coherence improper access control in Centralized Third Party Jars

CVE-2026-35308 · Severity: critical · CVSS 10 · Published 2026-06-17

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing a password. This could lead to the theft of sensitive data, service outages, or the compromise of other connected business systems.

Technical details

A vulnerability exists in the Centralized Third Party Jars component of Oracle Coherence. The flaw is classified as Improper Access Control (CWE-284) and is easily exploitable via the HTTP protocol. An unauthenticated remote attacker can exploit this to achieve a complete takeover of the Oracle Coherence instance. Due to a scope change (Status: Changed), a successful exploit may also allow the attacker to impact additional products beyond the initial target. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats