A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60244 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL). Its vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects the worst-case exploitation profile: network attack vector, low attack complexity, no privileges required, and no user interaction, combined with high impact to confidentiality, integrity, and availability. Because exploitation requires no authentication and can be carried out remotely over HTTP, any exposed instance is at significant risk of full compromise.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation), within Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.1.0.0
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory and apply the relevant fixes for the affected Oracle Coherence versions. No CISA KEV entry accompanied this record, so there is no confirmation of active exploitation in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60244, https://nvd.nist.gov/vuln/detail/CVE-2026-60244