Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical vulnerability. An attacker with low-level access to the network can exploit this to view, modify, or delete sensitive business data. Because Coherence is often integrated with other corporate systems, a successful attack could also compromise connected applications and services.
Technical details
A vulnerability in the Core component of Oracle Coherence (Fusion Middleware) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is notable for a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate Oracle Coherence environment. Successful exploitation can result in the unauthorized creation, deletion, or modification of all accessible data, as well as complete read access to sensitive information. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory