Executive brief
Oracle Coherence, a widely used data grid solution for high-speed data processing and storage, contains a critical security flaw. An unauthorized attacker can remotely take full control of the system over the network without needing any login credentials. This could lead to a total loss of data confidentiality, unauthorized modification of information, and complete service disruption.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.