CVE-2026-60238: Medium severity Oracle Oracle Coherence (Oracle Fusion Middleware - Core) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Organizations can determine exposure by identifying Oracle Coherence Core instances running one of these versions.
What does an attacker need to exploit this issue?
An attacker must have network access to the affected Oracle Coherence service via HTTP. No authentication or user interaction is required, but exploitation is described as difficult and has high attack complexity.
What access could a successful attacker gain?
A successful attacker could read a subset of accessible Oracle Coherence data and perform unauthorized update, insert, or delete operations on some accessible data. The scope may extend beyond Oracle Coherence and significantly affect additional products.