Junglewise Threat Intelligence

CVE-2026-60233: Oracle Coherence partial denial of service in Core component

CVE-2026-60233 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a vulnerability in its core component. A remote attacker with low-level user credentials can exploit this flaw over the network to disrupt the service. This could lead to a partial denial of service, potentially slowing down applications or impacting data availability for business operations.

Technical details

A vulnerability exists in the Core component of Oracle Coherence version 15.1.1.0.0. The flaw is classified as easily exploitable and requires network access via TCP. An attacker must possess low-privileged credentials to successfully execute the exploit. The primary impact is on availability, where a successful attack can result in a partial denial of service (DoS) of the Coherence cluster. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Coherence 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60233 was published to the NVD.

References

Related threats