CVE-2026-35310: Critical severity Oracle Oracle Coherence vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or restrict HTTP access to Oracle Coherence instances from untrusted networks. Place Coherence nodes behind a firewall, WAF, or network ACLs and allow HTTP access only from trusted management hosts or internal networks. If possible, isolate Coherence clusters from the public internet and restrict inbound HTTP to required IP ranges.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35310?
The severity of CVE-2026-35310 is critical with a score of 9.8.
How do I fix CVE-2026-35310?
To fix CVE-2026-35310, update affected Oracle Coherence versions to the latest secured releases.
What products are affected by CVE-2026-35310?
CVE-2026-35310 affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
What kind of attack can exploit CVE-2026-35310?
CVE-2026-35310 can be exploited by unauthenticated attackers with network access via HTTP.
What is the impact of CVE-2026-35310?
The impact of CVE-2026-35310 includes the potential compromise of Oracle Coherence, leading to data loss or unauthorized access.