
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60305 is an improper access control vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows a low-privileged attacker with network access via TCP to perform unauthorized data creation, deletion, modification, and limited read access on Oracle Coherence data. It carries a CVSS v3.1 base score of 7.1 (High) (Oracle CPU July 2026, Feedly). The vulnerability was published on July 21, 2026, and patched as part of Oracle's July 2026 Critical Patch Update.
The vulnerability is classified as CWE-284 (Improper Access Control), indicating that Oracle Coherence's Core component fails to properly enforce authorization boundaries for authenticated network users (Feedly). An attacker with low privileges and TCP network access can bypass access controls to perform unauthorized operations on Coherence data stores. The attack requires no user interaction and has low attack complexity, making it straightforward to exploit once network access is established. No specific technical write-ups or public proof-of-concept code have been identified at this time.
Successful exploitation allows a low-privileged attacker to perform unauthorized creation, deletion, or modification of critical Oracle Coherence data, as well as read a subset of data they are not authorized to access (Oracle CPU July 2026). The primary impacts are to data integrity (High) and confidentiality (Low), with no availability impact. In environments where Oracle Coherence is used as a distributed data grid or caching layer, unauthorized data modification could affect dependent applications and potentially facilitate further lateral movement within the infrastructure.
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.0024 (0.24%), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Oracle's own assessment notes the vulnerability is "easily exploitable" for authenticated low-privileged users, which may increase risk if exposed to untrusted network segments.
Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the July 2026 Critical Patch Update (Oracle CPU July 2026). Organizations should apply the CPU patches immediately. As interim mitigations, restrict network access to Oracle Coherence TCP ports to only trusted and authorized systems, implement network segmentation and firewall rules, and monitor Coherence access logs for unauthorized data access attempts (Feedly). Oracle strongly recommends against relying on network-level workarounds as a long-term solution.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."