Executive brief
Oracle Coherence is a distributed caching and data-sharing platform used in enterprise applications to improve performance and availability. A vulnerability in the Core component allows an authenticated attacker with network access to completely compromise Coherence and gain full control over cached data and operations, affecting confidentiality, integrity, and system availability.
Technical details
This vulnerability in Oracle Coherence's Core component is easily exploitable by a low-privileged, network-authenticated attacker via multiple protocols. The flaw allows an attacker to escalate privileges and achieve complete takeover of the Coherence system, affecting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The attack requires network access and authentication but does not require user interaction. Patch or mitigation information is not available in the provided advisory.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-09-15: disclosed