CVE-2026-60262: Critical severity Oracle Oracle Coherence vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 14.1.1.0.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 14.1.2.0.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Coherence (Core)to a version that resolves this vulnerability.Fixed in 15.1.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60262?
The severity of CVE-2026-60262 is critical with a CVSS score of 9.8.
Who is affected by CVE-2026-60262?
CVE-2026-60262 affects users of Oracle Coherence in the supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
How do I fix CVE-2026-60262?
To fix CVE-2026-60262, apply the latest security patch provided by Oracle for affected Oracle Coherence versions.
What type of attack does CVE-2026-60262 allow?
CVE-2026-60262 allows unauthenticated remote attackers to compromise Oracle Coherence using TCP network access.
What are the potential impacts of CVE-2026-60262?
The potential impacts of CVE-2026-60262 include a complete compromise of confidentiality, integrity, and availability for the affected systems.