Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security vulnerability in its core component. An attacker with basic network access and low-level user credentials can exploit this flaw to take full control of the system. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete shutdown of the data service.
Technical details
This vulnerability exists within the Core component of Oracle Coherence. It is classified as easily exploitable, requiring only low-privileged authentication and network access via the TCP protocol. The flaw allows an attacker to bypass security controls to achieve a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the impact suggests a significant failure in access control or input validation within the core service. Patches are typically released via the Oracle Critical Patch Update (CPU) program.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.