Junglewise Threat Intelligence

CVE-2026-60237: Oracle Coherence unauthorized data access in Core component

CVE-2026-60237 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a vulnerability in its core component. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive business data. This could lead to the exposure of internal information stored within the data grid.

Technical details

A vulnerability in the Core component of Oracle Coherence allows an unauthenticated attacker with network access via TCP to compromise the system. The flaw is classified as easily exploitable and does not require user interaction. Successful exploitation results in unauthorized read access to a subset of data managed by Oracle Coherence. The vulnerability affects versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats