← Back to Research Blog
CRITICAL CVE-2026-35308

Critical Unauthenticated HTTP Vulnerability in Oracle Coherence: Exploitation Pathways and Mitigations for Enterprise Defense

10.0
CRITICAL
oracle coherence
2026-08-10

Overview

CVE-2026-35308 is a CVSS 10.0 vulnerability in Oracle Coherence that permits unauthenticated attackers to achieve remote system takeover via HTTP. The flaw impacts multiple supported versions and enables scope-chaining attacks that compromise additional enterprise systems.


Technical Analysis

The vulnerability resides in Oracle Coherence's Centralized Third Party Jars component, exposing a deserialization or JAR-handling flaw exploitable through crafted HTTP requests. Attackers require no authentication, and the low complexity (AC:L) ensures rapid weaponization. Successful exploitation grants full control over the affected instance, with potential cascading effects on interconnected products due to the scope change (S:C) in the CVSS vector.

Enterprise & DIB Impact

Defense industrial base (DIB) entities and enterprises using Oracle Fusion Middleware in critical infrastructure face immediate risk. Compromise of Coherence deployments could disrupt mission-critical operations and expose sensitive defense data, while the scope change allows lateral movement into other enterprise systems.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512