Executive brief
Oracle Coherence, a widely used data grid solution for high-speed data processing and storage, contains a critical security flaw. An unauthorized attacker can remotely take full control of the system over the network without needing a username or password. This could lead to a complete compromise of sensitive data, service outages, and unauthorized access to the broader corporate environment.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (versions 12.2.1.4.0 and 14.1.1.0.0). The flaw is classified as easily exploitable, allowing a remote, unauthenticated attacker to gain full control over the Coherence instance via the HTTP protocol. The attack requires no user interaction and has a low complexity, resulting in a complete loss of confidentiality, integrity, and availability. While the specific vulnerability class (e.g., deserialization or injection) is not explicitly named in the advisory, the impact is a full system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60244 by Oracle