Junglewise Threat Intelligence

CVE-2026-60218: Oracle Coherence full compromise in Core component

CVE-2026-60218 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security vulnerability in its core component. An attacker with basic network access and low-level user credentials can exploit this flaw to take full control of the system. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete shutdown of the data service.

Technical details

This vulnerability exists within the Core component of Oracle Coherence. It is classified as easily exploitable, requiring only low-privileged authentication and network access via the TCP protocol. The flaw allows an attacker to bypass security controls to achieve a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the impact suggests a significant failure in access control or input validation within the core service. Patches are typically released via the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.

References

Related threats