Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a critical vulnerability in its core component. An attacker with low-level access to the local network segment can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive data, disruption of business operations, and potential unauthorized access to other connected enterprise systems.
Technical details
A vulnerability exists in the Core component of Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw is easily exploitable by a low-privileged attacker who has access to the physical communication segment (adjacent network) where the hardware executes. Successful exploitation results in a complete takeover of Oracle Coherence and carries a scope change, meaning the impact can extend to other products within the environment. The vulnerability affects confidentiality, integrity, and availability, and is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory