Executive brief
Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a critical security vulnerability. An unauthenticated attacker could remotely exploit this flaw over the network to gain full control of the Coherence environment. This could lead to the theft of sensitive business data, unauthorized modification of information, or a complete shutdown of the affected services.
Technical details
A vulnerability exists in the Core component of Oracle Coherence that allows for a complete system takeover. The flaw is exploitable by an unauthenticated attacker with network access via the TCP protocol. While the attack complexity is rated as high, suggesting specific timing or environmental conditions may be required, a successful exploit results in a total loss of confidentiality, integrity, and availability. The vulnerability affects multiple major versions including 12.2.x, 14.1.x, and 15.1.x. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory