Executive brief
Oracle Coherence, a widely used data grid solution for clustered applications, contains a critical security vulnerability in its core component. An unauthorized attacker can exploit this over the network to gain full control of the system without needing any login credentials. This could lead to the complete theft of sensitive data, disruption of business operations, and total compromise of the affected infrastructure.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability (CVSS 9.8). While specific CWE details were not provided in the advisory, the high impact and lack of authentication suggest a serious flaw in the handling of network-based requests or serialization within the core cluster communication protocols. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60300 by Oracle
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released