CVE-2026-60305
Oracle Coherence vulnerability analysis and mitigation

Overview

CVE-2026-60305 is an improper access control vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows a low-privileged attacker with network access via TCP to perform unauthorized data creation, deletion, modification, and limited read access on Oracle Coherence data. It carries a CVSS v3.1 base score of 7.1 (High) (Oracle CPU July 2026, Feedly). The vulnerability was published on July 21, 2026, and patched as part of Oracle's July 2026 Critical Patch Update.

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), indicating that Oracle Coherence's Core component fails to properly enforce authorization boundaries for authenticated network users (Feedly). An attacker with low privileges and TCP network access can bypass access controls to perform unauthorized operations on Coherence data stores. The attack requires no user interaction and has low attack complexity, making it straightforward to exploit once network access is established. No specific technical write-ups or public proof-of-concept code have been identified at this time.

Impact

Successful exploitation allows a low-privileged attacker to perform unauthorized creation, deletion, or modification of critical Oracle Coherence data, as well as read a subset of data they are not authorized to access (Oracle CPU July 2026). The primary impacts are to data integrity (High) and confidentiality (Low), with no availability impact. In environments where Oracle Coherence is used as a distributed data grid or caching layer, unauthorized data modification could affect dependent applications and potentially facilitate further lateral movement within the infrastructure.

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.0024 (0.24%), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Oracle's own assessment notes the vulnerability is "easily exploitable" for authenticated low-privileged users, which may increase risk if exposed to untrusted network segments.

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the July 2026 Critical Patch Update (Oracle CPU July 2026). Organizations should apply the CPU patches immediately. As interim mitigations, restrict network access to Oracle Coherence TCP ports to only trusted and authorized systems, implement network segmentation and firewall rules, and monitor Coherence access logs for unauthorized data access attempts (Feedly). Oracle strongly recommends against relying on network-level workarounds as a long-term solution.

Additional resources


SourceThis report was generated using AI

Related Oracle Coherence vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83412HIGH8.1
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesSep 15, 2026
CVE-2026-83415HIGH7.5
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesSep 15, 2026
CVE-2026-83416MEDIUM4.3
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesSep 15, 2026
CVE-2026-83414LOW2.5
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoNoSep 15, 2026
CVE-2026-83413LOW1.9
  • Oracle Coherence logoOracle Coherence
  • cpe:2.3:a:oracle:coherence
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management