A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network via HTTP, with no user interaction required.
What Is It
CVE-2026-60289 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, low complexity, and remote HTTP reachability makes this an attractive target. Because a successful attack yields full takeover, with high confidentiality, integrity, and availability impact, an exploited instance can be fully controlled by an attacker. The maximum exploitability sub-score of 3.9 underscores how readily the flaw can be reached and triggered.
What's Vulnerable
The following supported versions of Oracle Coherence (Oracle Fusion Middleware) are affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update. Organizations running affected versions should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes. At the time of this record, the CVE carries an NVD status of "Received," and no CISA KEV entry confirming active exploitation was supplied.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60289, https://nvd.nist.gov/vuln/detail/CVE-2026-60289