External risk intelligence

Oracle Coherence Core Vulnerability Allows Unauthenticated Network Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60210

Oracle Coherence is a data grid solution typically deployed within internal application tiers for distributed caching and data management. While it uses network protocols (TCP) and can be exposed if misconfigured or improperly segmented in cloud environments, it is not designed to be a public-facing service, making internet-level reachability possible but not the standard deployment pattern.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware, which could allow an unauthenticated attacker with network access to take control of the system. This issue carries a high CVSS score, indicating significant potential impacts on confidentiality, integrity, and availability. The main concern is confirming whether our environment utilizes Oracle Coherence and, if so, assessing our exposure.

  • Unauthenticated access can take over Oracle Coherence.
  • Critical impact on data and system availability.
  • Confirm Oracle Coherence use and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending network requests to Oracle Coherence. This could lead to a complete takeover of the product.

  • Attacker needs network access.
  • Triggered via network requests to Coherence.
  • Results in complete product takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, leading to a complete takeover of the system. This vulnerability impacts confidentiality, integrity, and availability.

  • Oracle Coherence system data.
  • Network access to TCP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Oracle Coherence, a component often managed by application owners or dedicated platform teams responsible for the Fusion Middleware stack. The initial step should be to identify all instances of Oracle Coherence, determine their network accessibility and business criticality, and then engage the accountable owner to plan remediation during the next maintenance window.

  • Application or Platform teams own this issue.
  • Verify Oracle Coherence network exposure.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used to store, manage, and process data across multiple servers. It acts as a distributed caching layer that enables high-performance applications to handle large volumes of data by keeping it readily accessible in memory rather than relying solely on traditional database lookups. It is a core component within the Oracle Fusion Middleware stack.

What does CVE-2026-60210 mean for system security?

This CVE represents a critical security flaw that allows an attacker to gain unauthorized control over the Oracle Coherence software. Because it involves a complete system takeover, it compromises the confidentiality, integrity, and availability of any data managed within that specific instance of the data grid.

How is this vulnerability triggered?

An attacker triggers this vulnerability by sending specific network requests via TCP directly to the Oracle Coherence service. Crucially, the attacker does not need a username or password to initiate this process. The vulnerability is tied to the software's network communication layer; it is not triggered by standard user interactions or logging into an application that merely uses Coherence as a backend.

Who should be concerned about this vulnerability?

Teams managing systems where Oracle Coherence is reachable over a network should be concerned. According to Halo Surface Signal, this software is typically found in internal application tiers, not on the public internet. However, if your configuration allows TCP traffic to reach these instances from untrusted or broader network segments, the risk increases, necessitating a review of your current network segmentation.

What should I do if I use Oracle Coherence?

First, conduct an inventory to locate all active Oracle Coherence instances within your environment. Once identified, evaluate their network accessibility to determine if they are exposed to unauthorized segments. Coordinate with the application owners or platform teams responsible for your middleware stack to prioritize these systems for security updates during your next scheduled maintenance window.

References