CVE-2026-60265: Medium severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Exploitation requires a high-privileged attacker who can log on to the infrastructure where Oracle Coherence is running. The attack vector is local and requires no user interaction.
Which Oracle Coherence versions are affected?
The affected supported versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The provided information does not identify any unaffected configuration within those versions.
What could an attacker access after successful exploitation?
Successful exploitation can provide unauthorized access to critical data or complete access to all data accessible to Oracle Coherence. Because the vulnerability has scope change, impacts may significantly affect additional products.