
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35309 is a critical improper access control vulnerability in the Oracle Coherence product of Oracle Fusion Middleware, specifically in the "Centralized Third Party Jars" component. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its unauthenticated, network-exploitable nature with full confidentiality, integrity, and availability impact (Oracle CSPU Jun 2026, NVD).
The vulnerability is classified as CWE-284 (Improper Access Control), residing in third-party JAR libraries bundled within Oracle Coherence. An unauthenticated remote attacker can exploit this flaw over HTTP with low attack complexity, requiring no privileges and no user interaction. The specific third-party component involved has not been publicly disclosed by Oracle beyond the "Centralized Third Party Jars" designation, but the attack vector and impact profile are consistent with a deserialization or remote code execution class of vulnerability in a bundled dependency. CISA's SSVC assessment classifies the vulnerability as automatable with total technical impact (Oracle CSPU Jun 2026, NVD).
Successful exploitation results in a full takeover of the affected Oracle Coherence instance, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, read or modify sensitive data managed by the Coherence distributed cache, and disrupt service availability. Given Oracle Coherence's role as a distributed data grid often integrated with enterprise middleware and applications, compromise could facilitate lateral movement into connected systems and exposure of sensitive application data (Oracle CSPU Jun 2026, NVD).
Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the June 2026 Critical Security Patch Update. Organizations should apply the relevant patches immediately by consulting the Fusion Middleware Patch Availability Document referenced in the advisory. As a temporary workaround, Oracle recommends restricting network access to Oracle Coherence instances by blocking HTTP access at the network perimeter and limiting exposure to trusted networks only. Oracle explicitly cautions that network-level blocking is not a long-term solution and does not address the underlying vulnerability (Oracle CSPU Jun 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."