Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical vulnerability in its core component. An attacker with access to the local network segment can completely take over the system without needing a username or password. This could lead to the theft of sensitive data, disruption of business operations, and total loss of system integrity.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is easily exploitable by an unauthenticated attacker who has access to the physical communication segment (adjacent network) where the hardware executes. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60211 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published