CVE-2026-35309
Oracle Coherence vulnerability analysis and mitigation

Overview

CVE-2026-35309 is a critical improper access control vulnerability in the Oracle Coherence product of Oracle Fusion Middleware, specifically in the "Centralized Third Party Jars" component. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its unauthenticated, network-exploitable nature with full confidentiality, integrity, and availability impact (Oracle CSPU Jun 2026, NVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), residing in third-party JAR libraries bundled within Oracle Coherence. An unauthenticated remote attacker can exploit this flaw over HTTP with low attack complexity, requiring no privileges and no user interaction. The specific third-party component involved has not been publicly disclosed by Oracle beyond the "Centralized Third Party Jars" designation, but the attack vector and impact profile are consistent with a deserialization or remote code execution class of vulnerability in a bundled dependency. CISA's SSVC assessment classifies the vulnerability as automatable with total technical impact (Oracle CSPU Jun 2026, NVD).

Impact

Successful exploitation results in a full takeover of the affected Oracle Coherence instance, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, read or modify sensitive data managed by the Coherence distributed cache, and disrupt service availability. Given Oracle Coherence's role as a distributed data grid often integrated with enterprise middleware and applications, compromise could facilitate lateral movement into connected systems and exposure of sensitive application data (Oracle CSPU Jun 2026, NVD).

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the June 2026 Critical Security Patch Update. Organizations should apply the relevant patches immediately by consulting the Fusion Middleware Patch Availability Document referenced in the advisory. As a temporary workaround, Oracle recommends restricting network access to Oracle Coherence instances by blocking HTTP access at the network perimeter and limiting exposure to trusted networks only. Oracle explicitly cautions that network-level blocking is not a long-term solution and does not address the underlying vulnerability (Oracle CSPU Jun 2026).

Additional resources


SourceThis report was generated using AI

Related Oracle Coherence vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60308CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoNoJul 21, 2026
CVE-2026-60306CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60309HIGH8.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60305HIGH7.1
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60307MEDIUM4.3
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management