A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60296 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.
The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network attack vector, low attack complexity, no required privileges, and no user interaction; with high impact to confidentiality, integrity, and availability.
Why It Matters
With a base score of 9.8 (CRITICAL) and full unauthenticated remote exploitation, this vulnerability offers attackers a direct path to seizing control of an affected Coherence instance. Because exploitation requires no credentials and no user interaction, any exposed TCP-reachable instance is at significant risk. There is no CISA KEV entry in the supplied source material, so active exploitation is not confirmed here; the severity alone warrants urgent attention.
What's Vulnerable
The following supported versions of Oracle Coherence are affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
The vulnerable component is the Coherence Core.
Patch Status
Oracle addressed this vulnerability in its Critical Patch Update for July 2026. Administrators should apply the fixes described in the Oracle Critical Patch Update Advisory (cpujul2026) as the required remediation, prioritizing any internet- or network-reachable Coherence deployments given the unauthenticated attack vector.
Sources
- Oracle Critical Patch Update Advisory – July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD – CVE-2026-60296: https://nvd.nist.gov/vuln/detail/CVE-2026-60296