CVE-2026-60309: High severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the physical communication segment/network path where Oracle Coherence executes, since the vulnerability is exploitable by an unauthenticated attacker with access to that physical communication segment.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60309?
The severity of CVE-2026-60309 is rated as high with a score of 8.8.
Which versions are affected by CVE-2026-60309?
The affected versions for CVE-2026-60309 include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
How do I fix CVE-2026-60309?
To fix CVE-2026-60309, upgrade to a non-affected version of Oracle Coherence as specified in Oracle's security advisory.
What type of attack does CVE-2026-60309 allow?
CVE-2026-60309 allows an unauthenticated attacker with physical access to exploit the vulnerability.
What components of Oracle Fusion Middleware are impacted by CVE-2026-60309?
CVE-2026-60309 impacts the Core component of the Oracle Coherence product within Oracle Fusion Middleware.