CVE-2026-35306
Oracle Coherence vulnerability analysis and mitigation

Overview

CVE-2026-35306 is an Improper Access Control vulnerability (CWE-284) in the Oracle Coherence product of Oracle Fusion Middleware, specifically within the Centralized Third Party Jars component. The affected version is Oracle Coherence 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.3 (Critical), reflecting its network-accessible, unauthenticated, and scope-changing nature (Oracle Advisory, NVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) and resides in the Centralized Third Party Jars component bundled within Oracle Coherence 15.1.1.0.0. An unauthenticated attacker with network access via HTTP can exploit this flaw with low attack complexity and no user interaction required. The scope is marked as "Changed," indicating that a successful attack can impact components beyond Oracle Coherence itself, potentially affecting other products in the Oracle Fusion Middleware ecosystem. No detailed technical write-up or public proof-of-concept code has been identified at this time (Oracle Advisory, NVD).

Impact

Successful exploitation allows an unauthenticated remote attacker to gain complete read access to all Oracle Coherence accessible data (high confidentiality impact) and perform unauthorized insert, update, or delete operations on some Coherence-accessible data (low integrity impact). There is no availability impact. Due to the scope change, attacks may significantly affect additional products beyond Oracle Coherence within the Fusion Middleware environment, increasing the risk of lateral data exposure across interconnected systems (Oracle Advisory, NVD).

Mitigation and workarounds

Oracle has released a patch for CVE-2026-35306 as part of the June 2026 Critical Security Patch Update (CSPU). Affected organizations running Oracle Coherence 15.1.1.0.0 should apply the patch immediately by following the guidance in the Fusion Middleware Patch Availability Document referenced in the advisory. As a temporary workaround, Oracle recommends blocking network access to Oracle Coherence instances via firewall rules and network segmentation to reduce exposure over HTTP. Monitoring access logs for unauthorized data access attempts targeting Coherence components is also advised until patching is complete (Oracle Advisory).

Community reactions

The vulnerability was noted in community security feeds shortly after Oracle's June 17, 2026 disclosure, with references appearing on Mastodon and threat radar aggregators within hours of publication. No significant independent researcher commentary or major media coverage specific to CVE-2026-35306 has been identified beyond standard vulnerability digest reporting (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Coherence vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60308CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoNoJul 21, 2026
CVE-2026-60306CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60309HIGH8.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60305HIGH7.1
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60307MEDIUM4.3
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management