Vulnerability in Oracle Coherence Product of Oracle Fusion Middleware
CVE-2026-60309
8.8HIGH
What is CVE-2026-60309?
An unauthenticated access vulnerability exists in Oracle Coherence, part of Oracle Fusion Middleware. This flaw allows an attacker with physical access to the communication segment connected to the hardware running Oracle Coherence to potentially take control of the product. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are susceptible to exploitation, leading to significant risks concerning confidentiality, integrity, and availability.
Affected Version(s)
Oracle Coherence 12.2.1.4.0
Oracle Coherence 14.1.1.0.0
Oracle Coherence 14.1.2.0.0