Executive brief
Oracle Coherence, a widely used data grid solution for clustered applications, contains a critical security vulnerability. An unauthenticated attacker can remotely take full control of the system over the network. This could lead to the complete theft of sensitive data, service outages, and may allow the attacker to compromise other connected business systems.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. The vulnerability is characterized by a 'scope change' (CVSS S:C), meaning a successful exploit can impact components beyond the immediate security scope of Oracle Coherence. This allows for a complete compromise of confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory