Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical vulnerability in its core component. An unauthorized attacker can exploit this over the network to gain full control of the system. This could lead to the theft of sensitive data, disruption of business operations, and complete compromise of the affected infrastructure.
Technical details
This vulnerability exists in the Core component of Oracle Coherence within the Oracle Fusion Middleware suite. It is classified as easily exploitable, requiring no authentication or user interaction (PR:N/UI:N). An attacker can exploit the flaw remotely over HTTP to achieve a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026. Security engineers should prioritize patching affected versions 12.2.1.4.0 through 15.1.1.0.0.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory