External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60212

Oracle Coherence is a distributed data grid used for caching and data management. While it uses network protocols (TCP) and can be accessed remotely, it is typically deployed within internal application tiers or backend clusters rather than directly exposed to the public internet in standard configurations.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware used for data management and caching. This issue could allow an unauthorized individual with network access to gain complete control over the Coherence system, potentially impacting confidentiality, integrity, and availability of data. The primary concern at this stage is to determine if your organization utilizes the affected Oracle Coherence product and to assess any potential exposure.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • High impact to data integrity, confidentiality, and availability.
  • Confirm relevance and assess potential exposure to Oracle Coherence.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Coherence by sending specially crafted network traffic. This bypasses the need for any login or prior access, leveraging a flaw in the Core component. Successfully exploiting this vulnerability allows an attacker to gain complete control over the Oracle Coherence system, impacting confidentiality, integrity, and availability.

  • No authentication required.
  • Network access over TCP.
  • Full system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Coherence. This vulnerability could lead to the complete takeover of the Oracle Coherence system, impacting confidentiality, integrity, and availability.

  • Oracle Coherence system.
  • Network access via TCP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence component within Oracle Fusion Middleware is vulnerable, impacting multiple supported versions. Given Coherence's role as a distributed data grid for caching and data management, platform or application teams responsible for its deployment and maintenance are likely accountable. The initial step should involve identifying all instances of Oracle Coherence within the environment, confirming their network accessibility and business criticality, and then assigning ownership for remediation planning based on the identified risk.

  • Platform or application teams should own resolution.
  • Verify Coherence deployment and network exposure.
  • Plan remediation based on risk and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed data grid software that organizations use to manage data and cache information across computing clusters. It acts as a backend infrastructure component within Oracle Fusion Middleware, designed to handle high volumes of data and improve application performance by keeping data readily available in memory.

What does CVE-2026-60212 mean?

CVE-2026-60212 refers to a critical security weakness in the Core component of Oracle Coherence. It allows an attacker to take complete control of the system. In technical terms, it represents a failure to properly handle network communications, which an unauthorized person can exploit to bypass all security controls and compromise the system's confidentiality, integrity, and availability.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted network traffic directly to the Oracle Coherence system over TCP. No login, password, or prior authorization is required to initiate the attack. It is important to note that typical, valid system administration traffic that follows expected protocol formats does not trigger this vulnerability; it requires specifically malicious data designed to exploit the underlying weakness.

Is my environment at risk from this vulnerability?

According to Halo Surface Signal, Oracle Coherence is generally deployed within internal application tiers or backend clusters rather than being directly connected to the public internet. While it is technically possible for an attacker to target the system if they have network access, the actual risk depends on whether your Coherence instances are reachable from untrusted networks or can be reached by an attacker already positioned within your internal network.

What should I do first to address this issue?

Your first step is to identify all instances of Oracle Coherence running in your environment to understand your footprint. Once you have a list of deployments, confirm their network accessibility and business criticality. Coordinate with the platform or application teams responsible for these systems to assess their exposure and begin planning for the necessary software updates provided by the vendor.

References