Junglewise Threat Intelligence

CVE-2026-60231: Oracle Coherence unauthorized data access in Core component

CVE-2026-60231 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a distributed data grid used for high-speed data processing and storage, contains a security vulnerability in its core component. An attacker with low-level user credentials can access the system over the network to view, modify, or delete sensitive business data. This could lead to unauthorized data manipulation or the exposure of private information stored within the data grid.

Technical details

A vulnerability in the Core component of Oracle Coherence allows for unauthorized data access and modification. The flaw is exploitable by a low-privileged attacker who has network access via the HTTP protocol. The root cause is not explicitly detailed but involves improper access controls within the core data handling logic. An attacker can successfully perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the data accessible to the Coherence instance. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of the CVE record
  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this fix

References

Related threats