
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35306 is an Improper Access Control vulnerability (CWE-284) in the Oracle Coherence product of Oracle Fusion Middleware, specifically within the Centralized Third Party Jars component. The affected version is Oracle Coherence 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.3 (Critical), reflecting its network-accessible, unauthenticated, and scope-changing nature (Oracle Advisory, NVD).
The vulnerability is classified as CWE-284 (Improper Access Control) and resides in the Centralized Third Party Jars component bundled within Oracle Coherence 15.1.1.0.0. An unauthenticated attacker with network access via HTTP can exploit this flaw with low attack complexity and no user interaction required. The scope is marked as "Changed," indicating that a successful attack can impact components beyond Oracle Coherence itself, potentially affecting other products in the Oracle Fusion Middleware ecosystem. No detailed technical write-up or public proof-of-concept code has been identified at this time (Oracle Advisory, NVD).
Successful exploitation allows an unauthenticated remote attacker to gain complete read access to all Oracle Coherence accessible data (high confidentiality impact) and perform unauthorized insert, update, or delete operations on some Coherence-accessible data (low integrity impact). There is no availability impact. Due to the scope change, attacks may significantly affect additional products beyond Oracle Coherence within the Fusion Middleware environment, increasing the risk of lateral data exposure across interconnected systems (Oracle Advisory, NVD).
Oracle has released a patch for CVE-2026-35306 as part of the June 2026 Critical Security Patch Update (CSPU). Affected organizations running Oracle Coherence 15.1.1.0.0 should apply the patch immediately by following the guidance in the Fusion Middleware Patch Availability Document referenced in the advisory. As a temporary workaround, Oracle recommends blocking network access to Oracle Coherence instances via firewall rules and network segmentation to reduce exposure over HTTP. Monitoring access logs for unauthorized data access attempts targeting Coherence components is also advised until patching is complete (Oracle Advisory).
The vulnerability was noted in community security feeds shortly after Oracle's June 17, 2026 disclosure, with references appearing on Mastodon and threat radar aggregators within hours of publication. No significant independent researcher commentary or major media coverage specific to CVE-2026-35306 has been identified beyond standard vulnerability digest reporting (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."