Junglewise Threat Intelligence

CVE-2026-60267: Oracle Coherence unauthorized data access in Core component

CVE-2026-60267 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw in its core component. An unauthenticated attacker can exploit this over the network to gain full access to the data stored within the system. This could lead to the unauthorized theft, modification, or deletion of sensitive business information, potentially compromising the integrity of applications relying on this data grid.

Technical details

A vulnerability exists in the Core component of Oracle Coherence (Fusion Middleware) that allows for unauthorized data access and manipulation. The flaw is categorized as easily exploitable and can be triggered by an unauthenticated attacker with network access via TLS. Successful exploitation grants the attacker the ability to read, create, delete, or modify all data accessible to Oracle Coherence. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats