Executive brief
Oracle Coherence, a widely used data grid solution for high-performance applications, contains a critical security vulnerability in its core component. An unauthorized attacker can exploit this flaw over the network to gain full control of the system without needing a username or password. This could lead to the complete theft of sensitive data, disruption of business operations, and total compromise of the affected infrastructure.
Technical details
This vulnerability exists in the Core component of Oracle Coherence within Oracle Fusion Middleware. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise the system. The exploit requires no user interaction and provides the attacker with full control over the Confidentiality, Integrity, and Availability of the Coherence instance. While the specific vulnerability class (e.g., deserialization or buffer overflow) is not explicitly named in the advisory, the impact is a complete system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60230 by Oracle and NVD.