A critical, easily exploitable vulnerability in Oracle Coherence lets a remote, unauthenticated attacker fully compromise the product over HTTP, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60242 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product. The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, no authentication, and low complexity means an attacker needs only HTTP access to a vulnerable instance to seize control. With high impact across all three security properties, a successful exploit hands an attacker full compromise of the affected Coherence deployment. The 9.8 score places this at the top of the severity scale.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation), within Oracle Fusion Middleware, component: Core. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.1.0.0
Patch Status
This CVE was assigned by Oracle ([email protected]) and is addressed in Oracle's Critical Patch Update for July 2026. Organizations running the affected Coherence versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. At the time of this record, the NVD entry is in "Received" status and no CISA KEV entry confirming active exploitation was supplied.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60242, https://nvd.nist.gov/vuln/detail/CVE-2026-60242