Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a security vulnerability in its core component. An attacker with basic user access to the network can exploit this to read, change, or delete sensitive business data. This could lead to data corruption or unauthorized disclosure of internal information.
Technical details
A vulnerability in the Core component of Oracle Coherence allows for unauthorized data manipulation and disclosure. The flaw is reachable over the network via TCP and requires low-level authenticated privileges (PR:L) for exploitation. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of the data stored within the Coherence grid. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial advisory published by Oracle and NVD