External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60215

Oracle Coherence is a data grid solution typically deployed in backend or internal infrastructure to support application clustering and data caching. While it uses TCP networking and can be exposed if misconfigured, it is not designed to be a public-facing service, edge gateway, or internet-accessible endpoint in standard architectural deployments.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by attackers without prior authentication who can access it over the network, potentially leading to a complete takeover of the Coherence system. The high severity score indicates significant impacts on confidentiality, integrity, and availability.

  • Unauthenticated network access can fully compromise the system.
  • Critical systems at risk of full takeover.
  • Confirm relevance and exposure in your environment.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending specially crafted network traffic over TCP, as the vulnerability in the Core component is easily exploitable by unauthenticated users. Successful exploitation allows an attacker to gain complete control over the Oracle Coherence instance.

  • Unauthenticated network access via TCP.
  • Vulnerability in Oracle Coherence Core component.
  • Complete takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could gain control of Oracle Coherence, impacting its confidentiality, integrity, and availability. This could occur when the product is accessible over a network via TCP, potentially affecting the stability and data managed by clustered applications.

  • Oracle Coherence product data and services.
  • Unauthenticated network access via TCP.
  • Takeover of the Oracle Coherence system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence component within Oracle Fusion Middleware is susceptible to a critical vulnerability. This issue is likely to impact platform or infrastructure teams responsible for managing Oracle Coherence deployments. The first practical step is to identify all instances of Oracle Coherence, determine their network accessibility and business criticality, and then confirm the accountable owner for each instance to plan remediation.

  • Platform and infrastructure teams should own the issue.
  • Verify network exposure and business criticality first.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution within Oracle Fusion Middleware used to cache data and support application clustering. It helps systems manage high volumes of information across distributed environments, acting as a high-performance layer that sits behind primary applications to improve speed and scalability.

How does CVE-2026-60215 impact Oracle Coherence?

This vulnerability affects the Core component of Oracle Coherence. It allows an unauthenticated attacker to send crafted network traffic to the system, which can result in a complete takeover of the affected instance. This means an attacker could potentially gain full control, compromising the confidentiality, integrity, and availability of the data and services it manages.

What triggers this Oracle Coherence vulnerability?

The vulnerability is triggered when an attacker sends specifically crafted network traffic to an Oracle Coherence instance over TCP. It does not require any prior authentication or user interaction. Conversely, the bug is not triggered if the service is unreachable via the network; it specifically requires network-level access to the Coherence component to succeed.

Do I need to worry if my Coherence instance is internal?

While Oracle Coherence is generally deployed in backend or internal infrastructure and is not intended to be a public-facing service, Halo Surface Signal notes it can be exposed if misconfigured. You should care if your internal network architecture or existing security boundaries could allow unauthorized access to these TCP services from untrusted segments.

How should I respond to CVE-2026-60215?

Begin by identifying all running instances of Oracle Coherence across your environment. Once mapped, verify their specific network accessibility to see if they are reachable beyond intended internal segments. Determine the business criticality of each instance and coordinate with the accountable technical owners to plan and prioritize your remediation steps.

References