Vulnerability in Oracle Coherence Product of Oracle Fusion Middleware
CVE-2026-60309

8.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60309?

An unauthenticated access vulnerability exists in Oracle Coherence, part of Oracle Fusion Middleware. This flaw allows an attacker with physical access to the communication segment connected to the hardware running Oracle Coherence to potentially take control of the product. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are susceptible to exploitation, leading to significant risks concerning confidentiality, integrity, and availability.

Affected Version(s)

Oracle Coherence 12.2.1.4.0

Oracle Coherence 14.1.1.0.0

Oracle Coherence 14.1.2.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.