External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60197

Oracle Coherence is a middleware product typically used for distributed caching and data grid services. While it supports network-based communication and can be reachable via TCP, it is generally deployed within internal application tiers or private networks to support backend infrastructure rather than being directly exposed to the public internet.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue could allow an attacker to gain complete control over the affected Oracle Coherence systems. While the vulnerability is easily exploitable and carries a high CVSS score, its potential impact is contingent on the specific deployment and network accessibility of Oracle Coherence within your organization. The primary concern at this stage is to confirm if this technology is in use and exposed.

  • Unauthenticated attackers can take over Coherence.
  • Confirms if specific Oracle middleware is exposed.
  • Assess relevance and exposure to your environment.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access can exploit a vulnerability in Oracle Coherence's Core component. This allows them to compromise the product, potentially leading to a full takeover.

  • Unauthenticated network access is required.
  • The Core component is the trigger point.
  • Risk includes complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence. Successful attacks may lead to a complete takeover of the Coherence system, impacting confidentiality, integrity, and availability.

  • Oracle Coherence system data.
  • Network access via TCP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Coherence, a component of Oracle Fusion Middleware, is likely managed by application owners and infrastructure or platform teams responsible for its deployment and operation. Given its potential for full takeover, the first practical step is to identify all instances of this technology, confirm their network reachability and business criticality, and then locate the accountable owners to prioritize remediation efforts.

  • Application and platform teams own the issue.
  • Verify network exposure and criticality.
  • Plan and coordinate remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a middleware product within the Oracle Fusion Middleware family. It functions as a distributed caching and data grid service, allowing applications to manage and process large volumes of data across multiple servers. It serves as backend infrastructure to improve performance and scalability for enterprise applications.

What kind of vulnerability is CVE-2026-60197?

This vulnerability is a security flaw in the Oracle Coherence Core component. It is classified as a critical issue because it allows an unauthorized party to gain full control over the affected system. The weakness permits an attacker to bypass authentication mechanisms and compromise the software's confidentiality, integrity, and availability.

How can an attacker trigger this vulnerability?

An attacker triggers this bug by gaining network access to the affected Oracle Coherence system via TCP. No prior authentication or user interaction is required for the exploit to succeed. Please note that internal network connectivity is sufficient; the vulnerability does not require the system to be exposed directly to the public internet to be reachable.

Do I need to worry if my Oracle Coherence is internal?

Yes. According to Halo Surface Signal, while Oracle Coherence is often deployed within private networks or application tiers, it remains reachable via TCP. If your internal network is accessible to unauthorized users or compromised systems, those parties could potentially reach and exploit the service. You should evaluate access paths regardless of public exposure.

What should I do first to address this?

Begin by identifying all instances of Oracle Coherence across your environment to understand your footprint. Confirm the network reachability of these systems and determine their business criticality. Once mapped, coordinate with the application or platform teams responsible for these services to prioritize and plan for the necessary updates or security configurations.

References