Denial of Service Vulnerability in Oracle Coherence from Oracle
CVE-2026-60304

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60304?

A vulnerability exists in Oracle Coherence, part of Oracle Fusion Middleware, that could be exploited by a low-privileged attacker with TCP network access. This vulnerability can facilitate unauthorized actions resulting in the potential for Oracle Coherence to face severe disruptions, including unresponsiveness, frequent crashes, or complete denial of service. The supported versions impacted include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Affected Version(s)

Oracle Coherence 12.2.1.4.0

Oracle Coherence 14.1.1.0.0

Oracle Coherence 14.1.2.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.