External risk intelligence

Oracle Coherence Unauthorized Data Access Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-60239

Oracle Coherence is a middleware component typically deployed in internal application tiers or backend clusters. While it supports HTTP access, it is not commonly exposed directly to the public internet in standard deployments, though it may be reachable if misconfigured or if specific components are inadvertently exposed.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue could allow unauthorized access and modification of critical data within Oracle Coherence and potentially impact other connected products. The vulnerability is easily exploitable by an attacker with network access and low privileges.

  • Attackers can access and alter sensitive data.
  • It affects critical middleware and potentially other products.
  • Confirm relevance and assess potential data exposure.

Attack Path

How an attacker could exploit the issue

An attacker with limited privileges and network access can target Oracle Coherence through an HTTP connection. This vulnerability, residing in the Core component of Oracle Fusion Middleware, allows unauthorized access and modification of critical data within Oracle Coherence and potentially other connected products.

  • Requires network access with low privileges.
  • Triggered via HTTP to Oracle Coherence.
  • Risk: Unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access via HTTP could potentially compromise Oracle Coherence. This could lead to unauthorized changes to critical data or complete access to all accessible data within Oracle Coherence, and may impact other connected Oracle Fusion Middleware products.

  • Critical Oracle Coherence data and services.
  • Network access via HTTP.
  • Unauthorized data modification or access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides in Oracle Coherence, a middleware component. Responsibility for addressing it likely falls to the platform or infrastructure teams managing the Oracle Fusion Middleware deployment, with coordination from application owners whose services rely on Coherence. The initial step involves identifying all instances of Oracle Coherence, determining their business criticality and network exposure, and then confirming the accountable owner before planning remediation.

  • Platform and application teams own this.
  • Verify Coherence instances and exposure.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a middleware component within the Oracle Fusion Middleware suite. It acts as an in-memory data grid that enables applications to scale by providing fast, reliable access to frequently used data across distributed clusters. It is commonly used as a caching layer or data store to help complex enterprise applications maintain high performance.

What does CVE-2026-60239 mean for security?

This vulnerability represents a significant flaw in the core component of Oracle Coherence. It allows an attacker with low privileges and network access to bypass security controls. Essentially, it permits unauthorized parties to read, modify, or delete sensitive data handled by the middleware, potentially affecting the integrity of connected systems due to its broad, cross-product reach.

How is this vulnerability triggered?

The flaw is triggered when an attacker sends specific requests over an HTTP connection to the Oracle Coherence service. It is important to note that the vulnerability does not require high-level administrative access; a low-privileged account with network reach to the Coherence component is sufficient to initiate an attempt. It is not triggered by standard, legitimate user interactions that do not involve malformed or unauthorized HTTP requests.

Is my Oracle Coherence deployment at risk?

According to Halo Surface Signal, Oracle Coherence is typically used in backend or internal application tiers rather than being directly connected to the internet. Your risk level depends on whether your specific configuration has inadvertently exposed these management or HTTP interfaces to the public network. You should check if your instances are accessible from outside your internal perimeter.

How should I respond to this threat?

Start by identifying all deployed instances of Oracle Coherence within your environment and mapping which systems rely on them. Coordinate with your infrastructure and application teams to verify the network placement of these services. Once you have an inventory, prioritize updates for any instances that are reachable over the network, focusing on those supporting the most critical business data.

References