CVE-2026-35308
Oracle Coherence vulnerability analysis and mitigation

Overview

CVE-2026-35308 is a critical improper access control vulnerability in the Oracle Coherence product of Oracle Fusion Middleware, specifically in the "Centralized Third Party Jars" component. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 10.0 (Critical), the maximum possible score (Oracle Advisory, NVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) and resides in third-party JAR libraries bundled within Oracle Coherence ("Centralized Third Party Jars" component). An unauthenticated attacker with network access via HTTP can exploit this flaw without any user interaction or special privileges, making it fully automatable. The scope change indicator in the CVSS vector confirms that successful exploitation can affect components beyond Oracle Coherence itself, potentially impacting other products in the Oracle Fusion Middleware ecosystem. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Oracle Advisory, NVD).

Impact

Successful exploitation results in a complete takeover of Oracle Coherence, with full impact to confidentiality, integrity, and availability. An unauthenticated remote attacker can execute arbitrary code, exfiltrate sensitive data, disrupt service availability, and potentially pivot to other connected Oracle Fusion Middleware products due to the scope change. The broad attack surface — requiring only HTTP network access with no credentials — significantly elevates the risk for organizations running exposed Coherence instances (Oracle Advisory, NVD).

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the June 2026 Critical Security Patch Update, published June 17, 2026. Oracle strongly recommends applying the patch immediately. As a temporary workaround, organizations should restrict network access to Oracle Coherence HTTP endpoints to only authorized clients, implement network segmentation to limit blast radius, and monitor for anomalous HTTP traffic targeting Coherence services. Patch availability details are documented in the Fusion Middleware patch documentation referenced in the Oracle advisory (Oracle Advisory).

Community reactions

The June 2026 Oracle CSPU attracted attention due to the inclusion of multiple CVSS 10.0 vulnerabilities across Oracle Fusion Middleware products, including CVE-2026-35308. Security coverage noted that the patch bundle addressed 245 vulnerabilities total, with Oracle Coherence receiving two perfect-score CVEs (CVE-2026-35308 and CVE-2026-35307). Community commentary highlighted the risk posed by third-party JAR vulnerabilities in enterprise middleware and the importance of prompt patching given the unauthenticated, network-exploitable nature of the flaw (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Coherence vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60308CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoNoJul 21, 2026
CVE-2026-60306CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60309HIGH8.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60305HIGH7.1
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60307MEDIUM4.3
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management