Junglewise Threat Intelligence

CVE-2026-60281: Oracle Coherence data compromise in Core component

CVE-2026-60281 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling. An attacker with access to the local network segment can bypass security controls to view, modify, or delete sensitive business data stored within the system. This could lead to significant data breaches or the corruption of critical operational information.

Technical details

A vulnerability in the Core component of Oracle Coherence allows for unauthorized access and data manipulation. The flaw is easily exploitable by an unauthenticated attacker who has access to the physical communication segment (adjacent network) where the hardware executing Oracle Coherence is located. Successful exploitation grants the attacker the ability to create, delete, or modify all data accessible to Oracle Coherence, as well as full read access to that data. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60281
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats