Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the network without needing any login credentials. This could lead to a total loss of data confidentiality, system integrity, and service availability.
Technical details
This vulnerability is classified as Improper Access Control (CWE-284) within the Centralized Third Party Jars component of Oracle Coherence. It is remotely exploitable via HTTP without authentication (PR:N) and requires no user interaction (UI:N). An attacker can leverage this flaw to achieve a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released