Executive brief
Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a critical security vulnerability in its core component. An unauthorized attacker can remotely gain full control over the system over the network without needing any login credentials. This could lead to a total compromise of the data grid, resulting in the theft of sensitive information, data corruption, or a complete shutdown of dependent business applications.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is categorized as easily exploitable and allows an unauthenticated attacker to achieve full system compromise via the network using the TCP protocol. Successful exploitation grants the attacker complete control over the Coherence instance, impacting confidentiality, integrity, and availability (CVSS 9.8). While the specific CWE is not detailed in the advisory, the 'takeover' description and network vector suggest a remote code execution or severe authentication bypass flaw. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial advisory publication by Oracle and NVD.