Unauthenticated Network Vulnerability in Oracle Coherence by Oracle
CVE-2026-60296
9.8CRITICAL
What is CVE-2026-60296?
A vulnerability exists in the Oracle Coherence component of Oracle Fusion Middleware, allowing unauthenticated attackers with network access via TCP to exploit the system. This flaw could lead to significant security risks, including unauthorized control of Oracle Coherence. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, making it essential for users to implement necessary security measures to protect against potential takeover.
Affected Version(s)
Oracle Coherence 12.2.1.4.0
Oracle Coherence 14.1.1.0.0
Oracle Coherence 14.1.2.0.0