Executive brief
Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, is affected by a security vulnerability in its core component. An unauthenticated attacker could remotely exploit this flaw to cause the system to crash or hang, leading to a total service outage. Additionally, the attacker may be able to modify, insert, or delete certain data stored within the system, potentially compromising business information.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (Oracle Fusion Middleware) that is exploitable via the HTTP protocol. The flaw is categorized as difficult to exploit (Attack Complexity: High) but requires no authentication or user interaction. Successful exploitation allows an unauthenticated attacker with network access to cause a complete denial-of-service (DoS) through repeated crashes or system hangs. Furthermore, the attacker can gain unauthorized integrity impacts, including the ability to update, insert, or delete a subset of data accessible to the Coherence cluster. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date