HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-35309Published Modified CNA oracle

CVE-2026-35309: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars)

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A critical remote code execution vulnerability affects Oracle Coherence (part of Oracle Fusion Middleware) in the Centralized Third Party Jars component, covering versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw is reachable over HTTP from any network location without credentials or user interaction, placing it at the highest CVSS tier. Successful exploitation results in full takeover of the Oracle Coherence instance, giving an attacker control over confidentiality, integrity, and availability. No upstream fix has been published yet; HarborGuard is tracking the advisory and will surface a patched-image rebuild the moment Oracle ships a fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that package Oracle Coherence or its bundled third-party jars. Any image in a connected registry or CI pipeline running an affected version (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0) is flagged automatically.

Available
Triage

HarborGuard scores this finding at CVSS 9.8 (Critical) and weights it against each customer environment's compliance policy to determine urgency and routing. Alerts are directed to the appropriate team inbox within each organization based on the image owner and policy configuration.

Available
Patch

No fix version has been published by Oracle for CVE-2026-35309. HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression test run, and a PR against affected workloads will be triggered without manual intervention once a fix version is confirmed.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle Coherence HTTP endpoint over the network; no local access or physical proximity is needed.

  • AuthenticationNot required

    No credentials of any privilege level are required; the vulnerable endpoint accepts unauthenticated requests.

  • Victim interactionNot required

    Exploitation is entirely attacker-driven and requires no action from any user or administrator.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other variable environmental factors.

Blast Radius

  • A successful attacker gains the ability to execute arbitrary code within the Oracle Coherence process, achieving full system takeover.
  • All data accessible to the Coherence instance, including cached application data and secrets, can be read by the attacker.
  • The attacker can write, modify, or delete persisted and in-memory data managed by Coherence, corrupting application state.
  • The attacker can crash or permanently disable the Coherence service, causing a denial of service for any application layer that depends on it.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-35309 as of the publication date, the immediate capability is continuous advisory monitoring. HarborGuard re-checks the Oracle advisory on every ingest cycle so that a patched-image rebuild becomes available to customers the moment Oracle publishes a fix version. In the interim, customers can apply compensating controls through HarborGuard's policy engine: network-policy isolation rules can be pushed to restrict HTTP access to Coherence endpoints to known internal IP ranges only, and egress filtering can limit lateral movement if a container is compromised. For customers who have opted into auto-remediation, the full rebuild, regression test, and PR flow will trigger automatically against affected workloads as soon as a fix version is confirmed upstream, with no manual steps required. Given the critical CVSS score of 9.8 and the unauthenticated network attack surface, prioritizing network-layer isolation of any image running the affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0) is strongly advised until Oracle ships a patch.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Coherence
    12.2.1.4.0 · 14.1.1.0.0 · 14.1.2.0.0 · 15.1.1.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References