External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60240

Oracle Coherence is a data grid solution typically deployed within internal application tiers to support backend services. While it uses TCP networking and can be exposed, it is not designed to be a public-facing edge service or internet-accessible gateway in standard deployment patterns.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue allows an unauthenticated attacker to potentially gain complete control of the Oracle Coherence system, impacting confidentiality, integrity, and availability. The main concern is to confirm if this specific technology is in use within our environment.

  • Unauthenticated access can seize Oracle Coherence.
  • Critical systems are at risk of full takeover.
  • Confirm if Oracle Coherence is deployed.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending network requests to Oracle Coherence. Since no authentication is required, an attacker with network access can directly target the vulnerable component. Successful exploitation allows the attacker to gain complete control over the Oracle Coherence system, potentially leading to data compromise or service disruption.

  • Unauthenticated network access required.
  • Attacker triggers vulnerability via network requests.
  • Complete system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to take over Oracle Coherence. Such a takeover could impact the confidentiality, integrity, and availability of the affected system.

  • System takeover.
  • Network access via TCP.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence, a data grid solution, likely impacts application owners and platform teams responsible for backend services. The first practical step is to identify all Oracle Coherence deployments, determine their reachability and business criticality, and then assign ownership for remediation planning based on risk.

  • Application or platform teams own the issue.
  • Verify Coherence deployment and network exposure.
  • Plan remediation within maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid software used by organizations to manage, cache, and process high volumes of data across distributed servers. It acts as a backend infrastructure layer that supports fast access to data for complex applications, rather than a standalone user-facing application.

What does CVE-2026-60240 mean for security?

This CVE represents a critical flaw where the system fails to properly secure its core operations. Because the vulnerability allows an attacker to bypass authentication, it effectively permits unauthorized entities to gain full control over the data grid, which could lead to unauthorized access to processed information or disruption of services.

How is CVE-2026-60240 triggered?

An attacker triggers this vulnerability by sending specific network requests via TCP to the affected Oracle Coherence component. It does not require a user to log in or perform any action. Please note that this issue is only relevant if the attacker can establish a direct network connection to the Coherence service; it cannot be triggered without this reachability.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is typically deployed within internal tiers rather than as a public-facing service. While you should prioritize systems reachable over public networks, internal environments could still be at risk if an attacker has already gained a foothold elsewhere in your private network.

How do I start responding to this threat?

First, conduct an inventory to locate all Oracle Coherence installations in your environment. Once identified, evaluate which systems are reachable by external or untrusted networks. After assessing these risks, coordinate with your platform teams to plan and schedule the necessary security updates during your next maintenance window.

References