Junglewise Threat Intelligence

CVE-2026-60213: Oracle Coherence denial of service and data manipulation in Core component

CVE-2026-60213 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, is affected by a security vulnerability in its core component. An unauthenticated attacker could remotely exploit this flaw to cause the system to crash or hang, leading to a total service outage. Additionally, the attacker may be able to modify, insert, or delete certain data stored within the system, potentially compromising business information.

Technical details

A vulnerability exists in the Core component of Oracle Coherence (Oracle Fusion Middleware) that is exploitable via the HTTP protocol. The flaw is categorized as difficult to exploit (Attack Complexity: High) but requires no authentication or user interaction. Successful exploitation allows an unauthenticated attacker with network access to cause a complete denial-of-service (DoS) through repeated crashes or system hangs. Furthermore, the attacker can gain unauthorized integrity impacts, including the ability to update, insert, or delete a subset of data accessible to the Coherence cluster. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats