Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing a password. This could lead to the theft of sensitive data, service outages, or the compromise of other connected business systems.
Technical details
A vulnerability exists in the Centralized Third Party Jars component of Oracle Coherence. The flaw is classified as Improper Access Control (CWE-284) and is easily exploitable via the HTTP protocol. An unauthenticated remote attacker can exploit this to achieve a complete takeover of the Oracle Coherence instance. Due to a scope change (Status: Changed), a successful exploit may also allow the attacker to impact additional products beyond the initial target. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date