Executive brief
Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability over the network to gain full control of the system. This could lead to the theft of sensitive data, disruption of business operations, and total compromise of the affected environment.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific vulnerability class (e.g., RCE, deserialization) is not explicitly named in the advisory, the CVSS score of 9.8 and the 'takeover' description indicate a complete bypass of security controls. Successful exploitation results in a total loss of confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users should refer to the Oracle July 2026 Critical Patch Update for remediation instructions.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60289
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released