Junglewise Threat Intelligence

CVE-2026-60244: Oracle Coherence remote compromise in Core component

CVE-2026-60244 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a widely used data grid solution for high-speed data processing and storage, contains a critical security flaw. An unauthorized attacker can remotely take full control of the system over the network without needing a username or password. This could lead to a complete compromise of sensitive data, service outages, and unauthorized access to the broader corporate environment.

Technical details

A critical vulnerability exists in the Core component of Oracle Coherence (versions 12.2.1.4.0 and 14.1.1.0.0). The flaw is classified as easily exploitable, allowing a remote, unauthenticated attacker to gain full control over the Coherence instance via the HTTP protocol. The attack requires no user interaction and has a low complexity, resulting in a complete loss of confidentiality, integrity, and availability. While the specific vulnerability class (e.g., deserialization or injection) is not explicitly named in the advisory, the impact is a full system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60244 by Oracle

References

Related threats