CVE-2026-35306: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
Metrics
- CVSS v3.1
- 9.3
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a critical-severity data exposure and tampering vulnerability in Oracle Coherence 15.1.1.0.0, specifically in its Centralized Third Party Jars component. The vulnerability is reachable over the network via HTTP with no authentication required and no user interaction needed, making it trivially exploitable from any host with network access to the service. Successful exploitation gives an attacker full read access to all data accessible by Oracle Coherence and limited write access to insert, update, or delete some of that data, with a scope change meaning the impact can spill over into adjacent systems beyond Coherence itself. No fix version has been published upstream; HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle ships a patch.
HarborGuard Coverage
Detection of CVE-2026-35306 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle Coherence 15.1.1.0.0. Any image carrying the affected component is flagged automatically in both registry scans and CI/CD pipeline checks.
AvailableTriage is available using the CVSS 3.1 base score of 9.3 (Critical), weighted further by each customer environment's compliance policy to surface the finding in the right severity tier and route it to the appropriate team inbox. Per-environment policy weighting ensures that organizations with stricter data-classification rules see this finding elevated above baseline Critical handling if their policy warrants it.
AvailableBecause no fix version has been published by Oracle, no patched-image rebuild is available yet. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released; for customers with auto-remediation enabled, that rebuild triggers a regression run and a PR opened against affected workloads without requiring manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Coherence HTTP endpoint over the network; the service must be exposed to an attacker-controlled host, whether on the internet or internally.
- AuthenticationNot required
No account or credential of any privilege level is required; the attacker can send malicious requests as an anonymous, unauthenticated caller.
- Victim interactionNot required
The attack is entirely server-side and requires no action from any user or administrator to trigger.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and requires no special race conditions, timing windows, or environmental preconditions beyond network access.
Blast Radius
- Reads all data accessible to Oracle Coherence, including cached application data, session state, and any sensitive records stored or proxied through the cluster.
- Inserts, updates, or deletes a subset of Oracle Coherence accessible data, allowing an attacker to corrupt or manipulate application state.
- Scope change applies, meaning the impact can extend beyond Oracle Coherence itself to other products or services that consume or trust data from the affected cluster.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35306, the immediate capability is continuous advisory monitoring. HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically as soon as Oracle ships a fix version; for customers with auto-remediation enabled, that rebuild will trigger a regression run and a PR opened against affected workloads. In the interim, compensating controls worth reviewing include network-policy isolation to restrict HTTP access to Oracle Coherence endpoints to only known internal consumers, egress filtering to prevent the Coherence JVM from initiating outbound connections that could amplify a compromise, and feature-flag or deployment-config gating to disable the Centralized Third Party Jars component if it is not required in the target environment. Given the Critical CVSS score of 9.3 and the scope-change characteristic, images carrying Oracle Coherence 15.1.1.0.0 are surfaced at the top of the HarborGuard finding queue until a patch is applied or the image is removed from active use.
- Oracle Corporation / Oracle Coherence15.1.1.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N