Executive brief
Oracle Coherence, a data grid solution used for high-speed data processing and storage in enterprise applications, contains a critical security vulnerability. An unauthenticated attacker can exploit this flaw over the network via HTTP to gain full control of the affected system. This could lead to a complete compromise of sensitive data, service disruption, and unauthorized access to the broader corporate infrastructure.
Technical details
This vulnerability exists in the Core component of Oracle Coherence within the Oracle Fusion Middleware suite. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the environment. The exploit requires no user interaction and has a low attack complexity, leading to a complete loss of confidentiality, integrity, and availability (CVSS 9.8). While the specific vulnerability class (e.g., deserialization or injection) is not explicitly named in the advisory, the impact is a full system takeover. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD