CVE-2026-60260: Infoleak
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 14.1.1.0.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 14.1.2.0.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 15.1.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60260?
CVE-2026-60260 has a medium severity rating of 5.3.
Which versions of Oracle Coherence are affected by CVE-2026-60260?
The affected versions of Oracle Coherence are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
How do I fix CVE-2026-60260?
To fix CVE-2026-60260, update your Oracle Coherence to the latest supported version provided by Oracle.
What type of vulnerability is CVE-2026-60260?
CVE-2026-60260 is classified as an information leak vulnerability.
Can CVE-2026-60260 be exploited without authentication?
Yes, CVE-2026-60260 can be exploited by an unauthenticated attacker with network access via HTTP.