Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a vulnerability that allows unauthorized individuals to access or modify data over the network. An attacker could exploit this to steal sensitive business information or corrupt data without needing a username or password. This poses a significant risk to data confidentiality and integrity for organizations using affected versions of the software.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (Fusion Middleware). The flaw is exploitable by an unauthenticated attacker via the HTTP protocol. Successful exploitation allows for unauthorized access to critical data or complete access to all data managed by Coherence, as well as unauthorized update, insert, or delete capabilities for some data. The vulnerability has a CVSS 3.1 base score of 8.2, reflecting high confidentiality and low integrity impacts. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD