External risk intelligence

Oracle Coherence Network Vulnerability Allows Unauthorized Data Access and Modification

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-60220

Oracle Coherence is a data grid solution typically deployed in internal, backend, or application-tier environments to facilitate data caching and clustering. While it uses network protocols, it is not designed to be directly exposed to the public internet in standard deployment patterns, though it may be reachable within distributed network architectures.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Oracle Coherence, a component within Oracle Fusion Middleware. It allows an unauthenticated attacker to potentially gain unauthorized access to or modify critical data. The ease of exploitation and the potential for a wide impact across connected products warrant attention.

  • Unauthenticated access to critical data.
  • Data integrity and unauthorized modification risks.
  • Confirm relevance and exposure within your environment.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can compromise Oracle Coherence by exploiting a vulnerability accessible over the network. This attack requires a user, other than the attacker, to interact with a crafted component. Successful exploitation could lead to unauthorized modifications or access to critical data, potentially impacting other connected products.

  • Entry via network access.
  • Triggered by user interaction.
  • Risk of unauthorized data access/modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain unauthorized access to critical data or modify data within Oracle Coherence. Successful exploitation requires user interaction and may impact other connected products, potentially leading to significant data breaches or manipulation.

  • Critical Oracle Coherence data.
  • Via network access with user interaction.
  • Unauthorized data modification or access.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a real-world scenario, the Oracle Coherence component, likely part of an internal data grid or application middleware infrastructure, would fall under the purview of platform or infrastructure teams. Given the potential for broad data impact, initial triage should focus on identifying all deployments, assessing their business criticality and network reachability, and then engaging the accountable application or service owner to plan remediation. Coordination with the vendor for potential fixes or guidance is also a key first step.

  • Platform or application owners should manage the issue.
  • Verify all Coherence deployments and their reachability.
  • Plan remediation based on criticality and vendor guidance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that serves as a caching and clustering layer within Oracle Fusion Middleware. It is used by enterprise applications to store data across multiple servers, enabling fast access and high availability for distributed systems. It acts as the backbone for managing shared data states in complex, high-performance computing environments.

How does CVE-2026-60220 impact software security?

This vulnerability represents a significant security flaw that enables unauthorized data manipulation or theft. It falls under the weakness class of improper access control, where the software fails to properly verify or restrict the actions of an unauthenticated party. Because it allows for a 'scope change,' a successful attack can potentially compromise not just the Coherence data grid, but also other interconnected systems that rely on it.

Do I need to worry about direct automated attacks for CVE-2026-60220?

No. The vulnerability is not triggered automatically by simple network scanning. Successful exploitation requires a specific precondition: human interaction. An attacker needs a legitimate user to interact with a crafted component or malicious input for the vulnerability to be triggered. If there is no user activity involving the affected interface, the risk of this specific exploit path is mitigated.

Is my Oracle Coherence deployment at risk?

Risk depends on your network architecture. According to Halo Surface Signal, Oracle Coherence is typically used in backend, internal, or application-tier environments and is not meant to be directly reachable from the public internet. However, you should assess if your specific deployment is reachable within your distributed network, as the vulnerability requires network access to initiate the attack sequence.

What should I do if I run Oracle Coherence?

Your first step is to locate all instances of Oracle Coherence across your infrastructure. Once identified, work with the relevant application or service owners to determine how these components are networked and verify their business criticality. Concurrently, consult the latest vendor security alerts for official patches or configuration guidance to address the vulnerability.

References