Executive brief
Oracle Coherence is a distributed data grid solution used by organizations to provide fast access to frequently used data and to scale applications. A critical vulnerability has been identified that allows an unauthorized person to gain full control over the Coherence environment over the network. This could lead to the theft of sensitive data, disruption of business operations, and total loss of system integrity.
Technical details
A vulnerability in the Core component of Oracle Coherence (versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) allows for a complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. While the specific vulnerability class (e.g., deserialization or injection) is not explicitly named in the advisory, the impact is rated at the highest level for confidentiality, integrity, and availability. Attackers can achieve full administrative control without any user interaction. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory