Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a vulnerability that could allow an attacker to take full control of the system. A successful exploit could lead to the theft of sensitive data, unauthorized modification of information, or a total service outage. Because this component is often integrated with other business applications, an attack here could potentially spread to other parts of the corporate network.
Technical details
A vulnerability exists in the Core component of Oracle Coherence (Fusion Middleware). The flaw is exploitable by a low-privileged attacker with network access via TCP, though Oracle notes the attack complexity is high. Successful exploitation results in a 'scope change' (CVSS S:C), meaning the attacker can impact components beyond the immediate security scope of Oracle Coherence. This can lead to a complete takeover of the affected product, impacting confidentiality, integrity, and availability. Affected versions include 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update July 2026