
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35307 is a critical improper access control vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It allows unauthenticated remote attackers to fully compromise affected Oracle Coherence instances via HTTP, with a scope change indicating potential impact on additional connected products. Affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU), and carries a CVSS v3.1 base score of 10.0 (Critical) (Oracle CSPU Jun 2026, NVD).
The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle Coherence, exploitable over HTTP without authentication, with low attack complexity and no user interaction required (NVD). The attack vector is network-based, meaning any attacker with HTTP access to the Coherence instance can trigger the vulnerability. The scope change (S:C) in the CVSS vector indicates that a successful exploit can affect resources beyond the vulnerable Coherence component itself, potentially impacting other products in the same environment. Oracle has not publicly disclosed the specific technical root cause or exploitation mechanism beyond the risk matrix entry (Oracle CSPU Jun 2026). No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation results in a complete takeover of Oracle Coherence, with high impact to confidentiality, integrity, and availability — enabling an attacker to read sensitive cached data, modify system data and configurations, and disrupt service availability. The scope change means attacks may significantly impact additional products connected to or dependent on the affected Coherence instance, increasing the potential blast radius beyond the directly vulnerable component. Given Oracle Coherence's role as an in-memory data grid often integrated with enterprise middleware, exploitation could facilitate lateral movement into broader Oracle Fusion Middleware environments (Oracle CSPU Jun 2026, NVD).
Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the June 2026 Critical Security Patch Update; organizations should apply these patches immediately (Oracle CSPU Jun 2026). As a temporary workaround prior to patching, Oracle recommends blocking network protocols required by the attack — specifically restricting HTTP access to Oracle Coherence instances to trusted networks only using firewalls or network access controls. Oracle strongly cautions that network-level mitigations are not a long-term solution and may break application functionality; testing on non-production systems before deployment is advised. Organizations running unsupported versions should upgrade to a supported release to receive patches.
The June 2026 Oracle CSPU attracted broad attention due to the inclusion of multiple CVSS 10.0 vulnerabilities across Oracle Fusion Middleware products, including CVE-2026-35307 and the related CVE-2026-35308 in Oracle Coherence. Security aggregators such as BeyondMachines noted the patch update addressed 245 vulnerabilities, highlighting the Oracle Coherence and WebLogic critical findings as particularly significant (BeyondMachines). Tenable released a Nessus detection plugin (ID 321539) for this vulnerability shortly after disclosure (Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."