Executive brief
Oracle Coherence, a widely used data grid solution for high-speed data processing and storage, contains a critical security flaw in its core component. An unauthorized attacker can exploit this over the network to gain full control of the system without needing a username or password. This could lead to a complete loss of data confidentiality, unauthorized modification of business information, and a total shutdown of the affected services.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. While the specific vulnerability class (e.g., deserialization) is not explicitly named in the summary, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad). Attackers can achieve full system takeover without user interaction. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60256 by Oracle