Junglewise Threat Intelligence

CVE-2026-60238: Oracle Coherence unauthorized data access in Core component

CVE-2026-60238 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a security vulnerability in its core component. An attacker could potentially read, modify, or delete a subset of the data stored within the system without needing a password. While the attack is difficult to perform, a successful exploit could impact other connected business applications that rely on this data.

Technical details

A vulnerability in the Core component of Oracle Coherence (Oracle Fusion Middleware) allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is characterized by a high attack complexity (AC:H) but results in a scope change (S:C), meaning the impact can extend beyond the Coherence environment to other products. Successful exploitation enables unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats