External risk intelligence

Oracle Coherence Core Remote Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60241

Oracle Coherence is a data grid solution often used as a backend service. While it can be deployed internally, the vulnerability is accessible via HTTP without authentication, making it reachable if deployed as an API or web-accessible service, which is a common pattern for middleware components in distributed application architectures.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by unauthenticated attackers over the network, potentially leading to a complete takeover of the Coherence system and impacting confidentiality, integrity, and availability. The main concern at this stage is to confirm relevance and exposure within our environment.

  • A serious security flaw exists in Oracle Coherence.
  • It could allow attackers to take over systems.
  • Confirm if Oracle Coherence is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending network requests over HTTP to a vulnerable Oracle Coherence component. This could allow them to gain complete control over the Coherence system.

  • Unauthenticated network access is required.
  • HTTP requests trigger the vulnerability.
  • Complete takeover of the system.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This occurs because the vulnerability is easily exploitable and affects the core component of Oracle Coherence when exposed over HTTP.

  • Oracle Coherence system takeover.
  • Network access via HTTP.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Coherence, accessible via HTTP without authentication, could allow an attacker to take over the system. Responsibility likely falls to the platform or application teams managing Oracle Coherence, with support from network and security teams for exposure assessment. The first step is to identify all instances of Oracle Coherence, determine their reachability and business criticality, and assign an owner for remediation planning.

  • Platform/Application teams own the issue.
  • Verify reachability and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that serves as a caching and data management layer within Oracle Fusion Middleware. It is commonly used by large-scale applications to enable high-speed data access, distributed processing, and reliable data storage across clustered server environments.

What does CVE-2026-60241 mean for the system?

This vulnerability represents a critical flaw in the Core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely. By sending specially crafted network requests, an unauthorized user can gain complete control over the system, effectively taking it over and compromising the data it manages.

How can an attacker trigger this vulnerability?

An attacker triggers this issue by sending malicious HTTP requests to the target Oracle Coherence component over the network. This is not a local-only bug; it requires network-based interaction. The vulnerability is not triggered by internal management traffic that avoids HTTP or by strictly authenticated administrative actions.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, this vulnerability is most relevant if your Oracle Coherence instance is deployed as an API or web-accessible service, as the flaw is reachable via HTTP. While often used as a backend service, any instance directly exposed to external network traffic requires immediate assessment of its reachability and purpose.

What should I do if I run Oracle Coherence?

Your first step is to perform a comprehensive inventory to identify all instances of Oracle Coherence in your environment. Once mapped, prioritize assessing the reachability of each instance—specifically those reachable via HTTP—and engage your platform or application teams to determine the business criticality of those specific services to plan effective remediation.

References