Executive brief
A vulnerability in Oracle Coherence, a data grid solution used for high-speed data processing and storage, allows an unauthorized attacker to disrupt services or access sensitive information. An attacker can remotely crash the system, causing a total service outage, or gain unauthorized access to read and modify data. This could lead to significant business disruption and data integrity issues without requiring any user interaction or login credentials.
Technical details
A vulnerability in the Core component of Oracle Coherence (version 15.1.1.0.0) allows an unauthenticated attacker with network access via TCP to compromise the system. The flaw is categorized as easily exploitable and does not require user interaction. Successful exploitation can lead to a frequently repeatable crash or hang (Denial of Service), as well as unauthorized read, update, insert, or delete access to a subset of data managed by Coherence. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Coherence 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published