External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60230

Oracle Coherence is a data grid solution typically deployed within internal application tiers, backend clusters, or middleware environments. While it uses TCP networking and can be exposed if misconfigured or used in specific distributed architectures, it is not designed to be a public-facing internet edge service or gateway.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, which is easily exploitable by an unauthenticated attacker over the network, could allow for a complete takeover of the affected Oracle Coherence systems, impacting confidentiality, integrity, and availability. The main concern at this stage is to confirm if this technology is in use within our environment.

  • An attacker can fully control Oracle Coherence systems.
  • Critical systems could be compromised without authentication.
  • Assess if Oracle Coherence is deployed within our organization.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending network requests over TCP. This vulnerability is easy to exploit and does not require any special privileges or user interaction. If successful, an attacker can gain complete control of the Oracle Coherence system.

  • Unauthenticated attacker with network access.
  • Network requests via TCP.
  • Full takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact Oracle Coherence by allowing an unauthenticated attacker with network access via TCP to compromise the system. This could potentially lead to a takeover of the Oracle Coherence environment, affecting its confidentiality, integrity, and availability.

  • Oracle Coherence systems.
  • Unauthenticated network access.
  • Takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Oracle Coherence, a component of Oracle Fusion Middleware. Ownership likely falls to the application owners or platform teams responsible for managing this data grid solution. The initial priority is to locate all instances of Oracle Coherence, assess their exposure and business criticality, and identify the accountable teams for remediation planning.

  • Application or Platform Teams.
  • Confirm network reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution used to store and manage large amounts of data across multiple servers. It functions as a middleware component within Oracle Fusion Middleware, helping applications scale by keeping data in memory for rapid access. Organizations typically use it to power the backend of high-performance distributed systems.

What does CVE-2026-60230 mean for system security?

This vulnerability is a severe flaw that allows an attacker to seize full control of an affected Oracle Coherence instance. Because the system fails to verify the identity of the person connecting to it, the attacker can execute commands with the same authority as the software itself, which compromises the confidentiality, integrity, and availability of the data stored within the grid.

How does an attacker trigger this vulnerability?

An attacker triggers this issue by sending specifically crafted network requests over TCP directly to the affected Oracle Coherence component. It does not require a legitimate user to click anything or perform any action. Please note that simply having the software installed is not enough; the system must be reachable over the network for the attacker to initiate the connection.

Why should I care about this if my systems are internal?

According to Halo Surface Signal, Oracle Coherence is generally deployed in backend clusters or internal tiers rather than at the internet edge. However, you should still care because if a different, compromised machine within your internal network has access to these ports, an attacker could move laterally to take over the data grid.

Do I need to take action to secure my environment?

Yes. Your first priority is to create an inventory of all Oracle Coherence installations within your organization. Once identified, work with the platform or application teams responsible for those specific instances to confirm their network reachability and prepare to apply the necessary security updates provided by Oracle.

References