CVE-2026-60307: Infoleak
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60307?
The severity of CVE-2026-60307 is medium, with a CVSS score of 4.3.
How do I fix CVE-2026-60307?
To mitigate CVE-2026-60307, upgrade to a non-affected version of Oracle Coherence as specified in Oracle's security advisories.
Which versions are affected by CVE-2026-60307?
Affected versions by CVE-2026-60307 include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
What type of vulnerability is CVE-2026-60307?
CVE-2026-60307 is classified as an infoleak vulnerability.
What conditions are required to exploit CVE-2026-60307?
CVE-2026-60307 can be easily exploited by a low privileged attacker with network access via HTTP.