Executive brief
Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a critical security vulnerability in its core component. An unauthorized attacker can exploit this flaw over the network via HTTP without needing any login credentials. A successful attack could allow a complete takeover of the affected system, potentially leading to the theft of sensitive data, service disruption, or unauthorized access to the broader corporate network.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is categorized as easily exploitable and requires no authentication or user interaction. An attacker can reach the vulnerable component over the network via the HTTP protocol. Successful exploitation grants the attacker full control over the Oracle Coherence instance, impacting confidentiality, integrity, and availability (CVSS 9.8). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60290
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released