External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60216

Oracle Coherence is a data grid solution typically deployed in backend application tiers or internal infrastructure to support middleware services. While it supports network-based communication, it is not traditionally exposed directly to the public internet, though it may be reachable within distributed environments or across internal network segments.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue allows unauthenticated attackers with network access to potentially take control of the Coherence system, impacting confidentiality, integrity, and availability with severe consequences. The main concern is confirming if this specific technology is in use within your environment and if it is exposed.

  • Remote attackers can seize control of Oracle Coherence.
  • Confirms critical systems require review and attention.
  • Assess Oracle Coherence usage and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Coherence by leveraging its network-accessible TCP interface. Since no authentication is required, an attacker with network access can directly interact with the vulnerable component, potentially leading to a complete takeover of the Coherence system.

  • Unauthenticated network access required.
  • Direct interaction with TCP interface.
  • Complete system takeover risk.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in Oracle Coherence could allow an unauthenticated attacker with network access to gain complete control over the Coherence system, impacting its confidentiality, integrity, and availability.

  • Oracle Coherence system data.
  • Via unauthenticated network access.
  • Complete system takeover possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence component within Oracle Fusion Middleware is susceptible to a critical vulnerability, easily exploitable by unauthenticated attackers over TCP, potentially leading to a full takeover. The primary responsibility for addressing this lies with the platform or middleware teams managing Oracle Coherence, in conjunction with security and network teams to assess exposure. The immediate first step is to identify all deployments of the affected Oracle Coherence product, determine their network reachability and business criticality, and then engage the accountable owners to plan a risk-based remediation strategy.

  • Platform/Middleware teams own remediation.
  • Verify Coherence deployment reachability.
  • Plan coordinated updates or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used within Oracle Fusion Middleware. It provides distributed caching and data management, allowing applications to store and access massive amounts of data across multiple servers simultaneously. It acts as a high-performance backend layer, ensuring data is available and consistent for complex enterprise applications that require rapid processing and scalability.

How does CVE-2026-60216 work?

This vulnerability allows an attacker to gain unauthorized control over the Coherence system without needing credentials. Because the software fails to properly authenticate incoming network requests, an attacker can interact directly with the core component. This bypass effectively grants them the same privileges as an authorized administrator, allowing them to manipulate the data or operations managed by the grid.

Do I need to be on the same network to trigger this bug?

Yes, an attacker must have network access to the target system to trigger the vulnerability. It relies on direct communication with the Coherence TCP interface. Importantly, this does not mean the bug is triggered by standard web browsing or local application usage; it requires the ability to send specific network-level commands directly to the Oracle Coherence component.

Why is Halo Surface Signal labeling this as a potential risk?

Halo Surface Signal flags this as 'Possible' because Oracle Coherence is typically found in backend or internal tiers, not directly on the public internet. However, it is often reachable within large distributed environments or across internal network segments. You should care if your internal network architecture allows unexpected connections to these backend middleware services, as that expands the attack surface beyond just public-facing systems.

What should I do first to address this CVE?

Your first step is to inventory where Oracle Coherence is deployed across your organization. Once you identify active instances, verify their network reachability to understand if they are accessible from untrusted segments. Coordinate with your middleware or platform teams to prioritize these systems based on their business criticality, and prepare to apply the security updates provided by the vendor.

References