CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-35304

Critical · CVSS 9.8

Oracle Coherence — Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / takeover via HTTPS

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-306

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols CoherenceCoreoracle.coherencecom.tangosolHTTPS endpointunauthenticated attackerCWE-306CVE-2026-35304
Keywords CVE-2026-35304Oracle Coherenceunauthenticatedmissing authenticationCoherence Core RCEOracle Fusion Middleware CoherenceCoherence HTTPS takeoverCWE-306 CoherenceOracle Coherence 12.2.1.4.0Oracle Coherence 14.1.1.0.0Oracle Coherence 14.1.2.0.0Oracle Coherence 15.1.1.0.0proof of concept Coherence 2026
Versions: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

References

Status: enriched · ingested 2026-06-19T12:00:04.000Z · profiled 2026-06-19T12:30:04.000Z