Unauthenticated Remote Access Vulnerability in Oracle Coherence by Oracle
CVE-2026-60297
9.8CRITICAL
What is CVE-2026-60297?
A vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware, that can be exploited by an unauthenticated attacker with network access via TCP. This flaw affects multiple supported versions, making it easy for malicious actors to compromise the system. Successful exploitation may lead to a complete takeover of Oracle Coherence, risking the confidentiality, integrity, and availability of the data. Organizations using the affected versions need to take immediate steps to mitigate this risk.
Affected Version(s)
Oracle Coherence 12.2.1.4.0
Oracle Coherence 14.1.1.0.0
Oracle Coherence 14.1.2.0.0