Junglewise Threat Intelligence

CVE-2026-60303: Oracle Coherence partial denial of service in Core component

CVE-2026-60303 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a security vulnerability in its core component. An attacker with basic user access to the network can exploit this flaw to disrupt the service, potentially causing a partial system outage. While this does not allow for data theft, it can impact the reliability of applications that depend on Coherence for real-time data management.

Technical details

This vulnerability exists in the Core component of Oracle Coherence within the Oracle Fusion Middleware suite. It is classified as a denial-of-service (DoS) vulnerability that can be triggered remotely via HTTP. An attacker requires low-level privileges (authenticated access) to successfully exploit the flaw. The impact is limited to a partial loss of availability of the Coherence service. The vulnerability is easily exploitable and has been addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication by Oracle and NVD
  • 2026-07-21: advisory: Oracle Critical Patch Update July 2026 released

References

Related threats