Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a security vulnerability in its core component. An attacker with low-level user credentials can access the system over the network to view sensitive information they are not authorized to see. While the attacker cannot modify or delete data, this could lead to the exposure of internal business information.
Technical details
A vulnerability in the Core component of Oracle Coherence allows for unauthorized data disclosure. The flaw is categorized as easily exploitable, requiring only low-privileged authentication and network access via the HTTP protocol. Successful exploitation results in a loss of confidentiality, allowing the attacker to read a subset of data managed by the Coherence cluster. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation guidance.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD