Executive brief
Oracle Coherence, a widely used data grid solution for high-performance applications, contains a critical security vulnerability. An unauthorized attacker can gain full control over the system remotely over the network without needing any login credentials. This could lead to a complete compromise of the application's data, service availability, and overall operations.
Technical details
A critical vulnerability exists in the Core component of Oracle Coherence (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60306 by Oracle