External risk intelligence

Oracle Coherence Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-60217

Oracle Coherence is a data grid solution typically deployed in backend, internal, or cluster-based architectures rather than directly facing the public internet. While it utilizes TCP network access and may be reachable in specific enterprise configurations, it is not a standard internet-facing gateway, web server, or public-facing endpoint in common deployment patterns.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue allows for unauthorized network access and could lead to a complete takeover of the Coherence system, potentially impacting other connected products. Given its critical severity, understanding the relevance to our environment is key.

  • An Oracle Coherence flaw allows easy network takeover.
  • Critical risk impacts data and systems broadly.
  • Verify if Oracle Coherence is used in our systems.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending network requests over TCP. This vulnerability is easily exploitable and does not require any prior authentication or specific user interaction. Successful attacks can lead to a complete takeover of the Coherence environment, potentially impacting other connected products.

  • Unauthenticated network access via TCP.
  • Exploitation of the Oracle Coherence component.
  • Complete takeover of the system.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Coherence, potentially leading to a takeover of the product. This vulnerability may also impact additional products that integrate with Oracle Coherence, depending on the deployment.

  • Oracle Coherence data and services.
  • Network access via TCP.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence product, often deployed as a backend data grid, typically falls under the responsibility of platform or infrastructure teams, with application owners needing to coordinate. The immediate priority is to locate all instances of Oracle Coherence, assess their reachability and business criticality, identify the accountable owner for each, and then prioritize remediation efforts based on risk.

  • Platform and application owners should address.
  • Verify all Coherence instances and their reachability.
  • Plan remediation during planned maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used to manage, store, and process large volumes of data across distributed systems. It serves as a high-performance caching layer in Oracle Fusion Middleware, helping applications scale by keeping frequently accessed information readily available in memory across a cluster of servers.

What does CVE-2026-60217 mean for system security?

This vulnerability represents a critical security flaw where the software fails to properly validate or restrict incoming network communications. Because the system does not require authentication, an attacker can send malicious TCP requests to the Core component of Oracle Coherence to gain unauthorized control, potentially compromising the integrity, confidentiality, and availability of the data grid.

How can an attacker trigger this vulnerability?

An attacker triggers this issue by sending specifically crafted network requests over TCP directly to the Oracle Coherence service. The vulnerability is triggered by network connectivity alone; it does not require the attacker to have a valid user account, nor does it rely on a user clicking a link or performing any action inside the application.

Is my Oracle Coherence instance at risk?

Risk depends on your deployment architecture. Halo Surface Signal notes that while Oracle Coherence is a data grid typically housed within backend or cluster-based internal networks, it remains vulnerable if reachable via TCP. If your Coherence instance is exposed to broader network segments, it is more accessible to unauthorized entities compared to instances strictly isolated in protected backend environments.

What should I do if I run Oracle Coherence?

Your first step is to inventory all systems running Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. Work with your platform and infrastructure teams to map which instances are reachable over the network. Once identified, prioritize these systems for patching or security configuration changes during your next maintenance window to mitigate the risk of unauthorized system takeover.

References