Executive brief
A vulnerability exists in Oracle Coherence, a data grid solution used for high-speed data processing and storage within enterprise applications. A low-privileged user with access to the underlying system could potentially gain full access to sensitive data or modify critical information, provided they can trick another user into performing a specific action. This could lead to a significant breach of data confidentiality and integrity across the affected infrastructure.
Technical details
This vulnerability affects the Core component of Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. It is a local attack vector requiring low privileges (PR:L) and high complexity (AC:H), involving a scope change (S:C) and mandatory user interaction (UI:R). An attacker with local infrastructure access can achieve unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by Oracle Coherence. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60245 was publicly released.