CVE-2026-60301: High severity Oracle Oracle Coherence (Core) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the unauthenticated network-accessible Denial of Service by restricting TCP network access to Oracle Coherence (Core) to only trusted systems, blocking all other inbound traffic at the network boundary/firewall.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60301?
The severity of CVE-2026-60301 is rated as high with a score of 7.5.
How do I fix CVE-2026-60301?
To fix CVE-2026-60301, upgrade to the latest patched version of Oracle Coherence.
What versions are affected by CVE-2026-60301?
The affected versions for CVE-2026-60301 are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
What type of attack does CVE-2026-60301 allow?
CVE-2026-60301 allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence.
Is there any data loss associated with CVE-2026-60301?
CVE-2026-60301 has no impact on confidentiality or integrity, but it can lead to a denial-of-service situation.