Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security vulnerability in its core component. An unauthorized attacker can exploit this flaw over a network to gain full control of the system. This could lead to the theft of sensitive data, disruption of business operations, and total compromise of the affected environment.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. While the specific vulnerability class (e.g., deserialization or injection) is not explicitly detailed in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad). Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.