CVE-2026-35307
Oracle Coherence vulnerability analysis and mitigation

Overview

CVE-2026-35307 is a critical improper access control vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It allows unauthenticated remote attackers to fully compromise affected Oracle Coherence instances via HTTP, with a scope change indicating potential impact on additional connected products. Affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU), and carries a CVSS v3.1 base score of 10.0 (Critical) (Oracle CSPU Jun 2026, NVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle Coherence, exploitable over HTTP without authentication, with low attack complexity and no user interaction required (NVD). The attack vector is network-based, meaning any attacker with HTTP access to the Coherence instance can trigger the vulnerability. The scope change (S:C) in the CVSS vector indicates that a successful exploit can affect resources beyond the vulnerable Coherence component itself, potentially impacting other products in the same environment. Oracle has not publicly disclosed the specific technical root cause or exploitation mechanism beyond the risk matrix entry (Oracle CSPU Jun 2026). No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation results in a complete takeover of Oracle Coherence, with high impact to confidentiality, integrity, and availability — enabling an attacker to read sensitive cached data, modify system data and configurations, and disrupt service availability. The scope change means attacks may significantly impact additional products connected to or dependent on the affected Coherence instance, increasing the potential blast radius beyond the directly vulnerable component. Given Oracle Coherence's role as an in-memory data grid often integrated with enterprise middleware, exploitation could facilitate lateral movement into broader Oracle Fusion Middleware environments (Oracle CSPU Jun 2026, NVD).

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the June 2026 Critical Security Patch Update; organizations should apply these patches immediately (Oracle CSPU Jun 2026). As a temporary workaround prior to patching, Oracle recommends blocking network protocols required by the attack — specifically restricting HTTP access to Oracle Coherence instances to trusted networks only using firewalls or network access controls. Oracle strongly cautions that network-level mitigations are not a long-term solution and may break application functionality; testing on non-production systems before deployment is advised. Organizations running unsupported versions should upgrade to a supported release to receive patches.

Community reactions

The June 2026 Oracle CSPU attracted broad attention due to the inclusion of multiple CVSS 10.0 vulnerabilities across Oracle Fusion Middleware products, including CVE-2026-35307 and the related CVE-2026-35308 in Oracle Coherence. Security aggregators such as BeyondMachines noted the patch update addressed 245 vulnerabilities, highlighting the Oracle Coherence and WebLogic critical findings as particularly significant (BeyondMachines). Tenable released a Nessus detection plugin (ID 321539) for this vulnerability shortly after disclosure (Tenable).

Additional resources


SourceThis report was generated using AI

Related Oracle Coherence vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60308CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoNoJul 21, 2026
CVE-2026-60306CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60309HIGH8.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60305HIGH7.1
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60307MEDIUM4.3
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management