A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over TCP.
What Is It
CVE-2026-60230 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, low attack complexity, and no required privileges or user interaction makes this flaw trivially exploitable by a remote attacker. Because a successful attack results in full takeover of Oracle Coherence, an attacker could gain complete control over affected in-memory data grid deployments. The maximum impact ratings across confidentiality, integrity, and availability underscore the severity for any exposed instance.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation). Per the NVD record, the following supported versions are affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
This vulnerability is addressed in Oracle's July 2026 Critical Patch Update. Organizations running affected Oracle Coherence versions should apply the fixes provided in that Critical Patch Update advisory. No CISA KEV entry accompanies the supplied source material, so there is no confirmation of active exploitation in the data provided.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60230, https://nvd.nist.gov/vuln/detail/CVE-2026-60230