Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a critical security flaw. An unauthorized attacker can remotely take full control of the affected system over the network without needing a username or password. This could lead to a total loss of data confidentiality, system integrity, and service availability.
Technical details
A vulnerability in the Core component of Oracle Coherence (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. The attack does not require user interaction and has a low complexity, resulting in high impacts to confidentiality, integrity, and availability (CVSS 9.8). While the specific vulnerability class (e.g., deserialization or injection) is not explicitly named in the summary, the impact and vector are consistent with remote code execution or full authentication bypass. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD