Critical Unauthenticated HTTP Vulnerability in Oracle Coherence: Exploitation Pathways and Mitigations for Enterprise Defense
Overview
CVE-2026-35308 is a CVSS 10.0 vulnerability in Oracle Coherence that permits unauthenticated attackers to achieve remote system takeover via HTTP. The flaw impacts multiple supported versions and enables scope-chaining attacks that compromise additional enterprise systems.
Technical Analysis
The vulnerability resides in Oracle Coherence's Centralized Third Party Jars component, exposing a deserialization or JAR-handling flaw exploitable through crafted HTTP requests. Attackers require no authentication, and the low complexity (AC:L) ensures rapid weaponization. Successful exploitation grants full control over the affected instance, with potential cascading effects on interconnected products due to the scope change (S:C) in the CVSS vector.
Enterprise & DIB Impact
Defense industrial base (DIB) entities and enterprises using Oracle Fusion Middleware in critical infrastructure face immediate risk. Compromise of Coherence deployments could disrupt mission-critical operations and expose sensitive defense data, while the scope change allows lateral movement into other enterprise systems.
Recommended Actions
- Purge unsupported Oracle Coherence versions (12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0) from active environments
- apply vendor-published patches immediately if available for your environment
- Network-segment Coherence endpoints from untrusted zones and deploy HTTP-level WAF rules to block anomalous header patterns.
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →