Junglewise Threat Intelligence

CVE-2026-60214: Oracle Coherence data compromise in Core component

CVE-2026-60214 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a vulnerability that allows an attacker to compromise the system. An attacker with low-level access to the local network segment can gain full control over the data stored within the grid, including the ability to view, modify, or delete sensitive information. This could lead to significant data breaches or the corruption of critical business information across multiple integrated applications.

Technical details

A vulnerability exists in the Core component of Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is easily exploitable by a low-privileged attacker who has access to the physical communication segment (adjacent network) where the hardware executes. Successful exploitation results in a scope change, potentially impacting additional products integrated with the data grid. The attacker can achieve unauthorized creation, deletion, or modification of all accessible data, as well as complete confidentiality loss of critical data. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats