Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a security vulnerability in its core component. A high-privileged attacker with network access could exploit this to gain unauthorized access to sensitive business data or modify existing records. This could lead to data breaches or the corruption of critical information managed by the middleware.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (Oracle Fusion Middleware). The flaw is easily exploitable by a high-privileged attacker who has network access via HTTP. Successful exploitation allows for unauthorized access to all Coherence-accessible data (Confidentiality impact) and unauthorized update, insert, or delete access to some data (Integrity impact). The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60270 by Oracle