CVE-2026-35310
Oracle Coherence vulnerability analysis and mitigation

Overview

CVE-2026-35310 is a critical Improper Access Control vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its unauthenticated, network-exploitable nature with total impact across confidentiality, integrity, and availability (Oracle CSPU Jun 2026, Feedly).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) in the Core component of Oracle Coherence. An unauthenticated remote attacker can exploit this flaw over HTTP with low attack complexity, requiring no privileges or user interaction. The flaw allows the attacker to bypass access controls and achieve full takeover of the Oracle Coherence service. Oracle has not publicly disclosed the specific technical mechanism, which is consistent with its standard vulnerability disclosure policy (Oracle CSPU Jun 2026, Feedly). No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation results in complete takeover of the Oracle Coherence instance, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker can read sensitive cached data, modify or delete information managed by the Coherence data grid, and disrupt service availability. Given Coherence's role as a distributed in-memory data grid often integrated with enterprise middleware, compromise could facilitate lateral movement into connected Oracle Fusion Middleware components or backend systems (Oracle CSPU Jun 2026, Feedly).

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the June 2026 Critical Security Patch Update, available as of June 17, 2026. Oracle strongly recommends applying the patch immediately, as the vulnerability is easily exploitable without authentication. As a temporary workaround, organizations should restrict network access to Oracle Coherence instances to authorized systems only and disable HTTP access if not required for legitimate operations. Customers should refer to the Fusion Middleware patch availability documentation via My Oracle Support (Doc ID KA1182) for specific patch instructions (Oracle CSPU Jun 2026).

Community reactions

Oracle's June 2026 CSPU advisory highlighted CVE-2026-35310 among a broader set of 106 Fusion Middleware patches, with several Oracle Coherence vulnerabilities rated at 9.8 or 10.0 CVSS scores, drawing attention to the severity of the Coherence product family's exposure. Social media activity was noted on Bluesky shortly after disclosure, and the vulnerability was indexed by security aggregators including VulDB and cve.report (Oracle CSPU Jun 2026, Feedly). No significant independent researcher commentary or detailed technical write-ups have been published as of the time of this report.

Additional resources


SourceThis report was generated using AI

Related Oracle Coherence vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60308CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoNoJul 21, 2026
CVE-2026-60306CRITICAL9.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60309HIGH8.8
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60305HIGH7.1
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026
CVE-2026-60307MEDIUM4.3
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management