Junglewise Threat Intelligence

CVE-2026-60282: Oracle Coherence unauthorized data access in Core component

CVE-2026-60282 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a security vulnerability in its core component. An attacker with basic user credentials can access the system over the network to view, modify, or delete sensitive business data. This could lead to unauthorized data manipulation or the exposure of confidential information stored within the data grid.

Technical details

This vulnerability exists in the Core component of Oracle Coherence. It is classified as easily exploitable, requiring only low-privileged authentication and network connectivity via TCP. An attacker can exploit this flaw to gain unauthorized read access to a subset of Coherence-accessible data, as well as unauthorized update, insert, or delete access. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60282
  • 2026-07-21: advisory: Oracle released security alert cpujul2026

References

Related threats