External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60232

Oracle Coherence is a middleware component often used to support internet-facing applications, APIs, and services. While it typically resides in the application tier, it is frequently exposed to network requests over HTTP as part of web-based infrastructure and service endpoints, making internet-reachability a common deployment pattern.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by unauthenticated attackers over the network via HTTP, potentially leading to a complete takeover of the Coherence system. The high CVSS score indicates significant impacts on confidentiality, integrity, and availability.

  • Unauthenticated attackers can fully control the system.
  • This impacts core middleware, potentially affecting many services.
  • Confirm relevance and assess exposure to Oracle Coherence.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending network requests over HTTP to an exposed Oracle Coherence component. Because no authentication is required, a remote attacker could trigger the vulnerability, potentially leading to a complete takeover of the affected system.

  • Unauthenticated network access required.
  • Vulnerability triggered via HTTP requests.
  • Risk of complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This means an attacker could gain full control over the Oracle Coherence environment and its underlying resources.

  • Oracle Coherence system.
  • Network access via HTTP.
  • Complete takeover of the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability in Oracle Coherence, a middleware component that often supports internet-facing applications and services. The first practical step is to identify all instances of Oracle Coherence, confirm their network exposure and business criticality, and then assign an accountable owner to plan remediation based on the assessed risk.

  • Assign ownership to the application or platform team.
  • Verify network reachability and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a middleware component within Oracle Fusion Middleware. It provides distributed caching and data grid capabilities, allowing applications to store and manage data across multiple servers to improve performance and scalability. It is frequently used as the backend infrastructure for high-traffic web applications, APIs, and microservices that require rapid data access.

What does CVE-2026-60232 mean for system security?

This vulnerability represents a critical security flaw that allows unauthorized parties to compromise the Oracle Coherence environment. In technical terms, it is a high-severity issue that lacks any requirement for user authentication, meaning the system cannot verify who is sending requests. If triggered, it grants an attacker the ability to gain full control over the component, potentially impacting the confidentiality, integrity, and availability of your data.

How is this Oracle Coherence vulnerability triggered?

The flaw is triggered when an attacker sends specific, unauthorized network requests over HTTP to an affected Oracle Coherence instance. It does not require any prior account access or interaction from a legitimate user. It is important to note that internal, non-networked requests or connections that do not use the HTTP protocol are not the intended delivery mechanism for this specific exploit.

Is my Oracle Coherence instance at high risk?

According to Halo Surface Signal, this software is frequently deployed in roles that support internet-facing services, making it a likely target for remote access. If your Coherence instances are reachable over the internet via HTTP, they are at higher risk. You should prioritize assessing these public-facing endpoints first, as they are most accessible to external threats.

What should I do first to address this CVE?

Begin by creating an inventory of all Oracle Coherence deployments within your environment. Once identified, confirm which instances are accessible over the network and determine their business criticality. Assign clear ownership to the relevant application or platform teams so they can prepare for remediation steps, such as applying vendor-supplied updates once they are available.

References