Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage in enterprise applications, contains a critical security vulnerability. An attacker who has access to the same local network or physical communication segment as the affected hardware can take complete control of the Coherence system. This could lead to the theft of sensitive data, unauthorized modification of information, or a total shutdown of the service.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (part of Oracle Fusion Middleware). The flaw is easily exploitable and allows an unauthenticated attacker with access to the physical communication segment (adjacent network) to compromise the system. Successful exploitation results in a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60261 and has a CVSS 3.1 base score of 8.8. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD