Junglewise Threat Intelligence

CVE-2026-60295: Oracle Coherence remote takeover in Core component

CVE-2026-60295 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a vulnerability that could allow an attacker to take full control of the system. A successful exploit could lead to the theft of sensitive data, unauthorized modification of information, or a total service outage. Because this component is often integrated with other business applications, an attack here could potentially spread to other parts of the corporate network.

Technical details

A vulnerability exists in the Core component of Oracle Coherence (Fusion Middleware). The flaw is exploitable by a low-privileged attacker with network access via TCP, though Oracle notes the attack complexity is high. Successful exploitation results in a 'scope change' (CVSS S:C), meaning the attacker can impact components beyond the immediate security scope of Oracle Coherence. This can lead to a complete takeover of the affected product, impacting confidentiality, integrity, and availability. Affected versions include 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Affected products

  • Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update July 2026

References

Related threats