Oracle Coherence Vulnerability in Fusion Middleware Affects Several Versions
CVE-2026-60305

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60305?

An easily exploitable flaw exists within the Oracle Coherence component of Oracle Fusion Middleware, affecting multiple versions. This vulnerability can be leveraged by low-privileged attackers with network access via TCP, posing a serious risk to data integrity and confidentiality. Successful exploitation grants unauthorized users the ability to create, delete, or modify critical data, leading to significant breaches and compromises of data within the affected Oracle Coherence instances.

Affected Version(s)

Oracle Coherence 12.2.1.4.0

Oracle Coherence 14.1.1.0.0

Oracle Coherence 14.1.2.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.