Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical vulnerability in its core component. An unauthenticated attacker could exploit this to gain full access to sensitive business data, allowing them to read, modify, or delete information. While the attack requires a legitimate user to perform an action, a successful breach could spread beyond Coherence to impact other integrated corporate systems.
Technical details
A vulnerability in the Core component of Oracle Coherence (Fusion Middleware) allows an unauthenticated attacker with network access via TCP to compromise the system. The vulnerability is characterized by a CVSS 3.1 score of 9.3, indicating high confidentiality and integrity impacts with a scope change (S:C). Exploitation is considered easy but requires human interaction from a person other than the attacker (UI:R). Successful exploitation can result in unauthorized creation, deletion, or modification of all accessible data within Oracle Coherence, and potentially impact additional products integrated with the middleware. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication by Oracle
- 2026-07-21: advisory: NVD record published