Executive brief
Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a vulnerability in its core component. A low-privileged user with existing access to the server where the software is running can exploit this flaw to gain full control over the Coherence environment. This could lead to the unauthorized access, modification, or deletion of sensitive cached data and disruption of critical business applications.
Technical details
A vulnerability exists in the Core component of Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where Coherence is executing. Successful exploitation allows a low-privileged attacker to achieve a complete compromise of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released