Junglewise Threat Intelligence

CVE-2026-60248: Oracle Coherence compromise in Core component

CVE-2026-60248 · Severity: critical · CVSS 9.3 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security vulnerability in its core component. An attacker who has gained access to the underlying server infrastructure can fully take over the Coherence system without needing a username or password. This could lead to the theft of sensitive data, service outages, and may allow the attacker to compromise other connected business systems.

Technical details

A vulnerability in the Core component of Oracle Coherence allows for a complete system takeover. The flaw is categorized as easily exploitable but requires the attacker to have existing logon access to the infrastructure where Oracle Coherence is executing (Local attack vector). Despite the local requirement, the vulnerability does not require prior authentication to the Coherence service itself (PR:N) and involves a scope change (S:C), meaning a successful exploit can impact components beyond the immediate security scope of Oracle Coherence. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats