External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60242

Oracle Coherence is typically used as an internal-facing data grid or caching layer within enterprise applications. While the vulnerability is reachable via HTTP, it is not standard design for such components to be directly exposed to the public internet, though it remains plausibly reachable in some specific deployment configurations.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Oracle Coherence, a component within Oracle Fusion Middleware. The issue allows an unauthenticated attacker with network access to potentially take over the system, leading to significant impacts on confidentiality, integrity, and availability. While the vulnerability is exploitable over HTTP, its typical use as an internal component means the primary concern is confirming its relevance and exposure within our environment.

  • Unauthenticated attackers can take over Oracle Coherence systems.
  • Critical vulnerability impacting data and system availability.
  • Confirm relevance and exposure within our environment.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending network requests over HTTP. This vulnerability allows an unauthenticated attacker with network access to gain complete control of the Oracle Coherence system.

  • Attacker needs network access.
  • Unauthenticated HTTP requests trigger vulnerability.
  • Compromise of the entire system.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could impact the confidentiality, integrity, and availability of data and services managed by Oracle Coherence.

  • System takeover of Oracle Coherence.
  • Unauthenticated network access via HTTP.
  • Disruption of data and services.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining ownership for Oracle Coherence requires identifying which team manages the Fusion Middleware platform and the applications that rely on Coherence for data caching or distribution. The first practical step is to locate all instances of Oracle Coherence within your environment, assess their network accessibility and business criticality, and then engage the accountable application or platform owner to plan a coordinated remediation.

  • Identify accountable application/platform owners.
  • Verify Coherence instance exposure and criticality.
  • Plan coordinated maintenance window remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a specialized software component within the Oracle Fusion Middleware suite. It functions as an in-memory data grid, providing distributed caching and data management services. Developers use it to help enterprise applications process large volumes of data quickly by keeping that data accessible across multiple servers in real-time.

How should I interpret the security weakness in CVE-2026-60242?

This vulnerability is a high-severity flaw that enables an unauthenticated attacker to take full control of the Oracle Coherence component. It represents a critical breakdown in system security, allowing someone without authorized access to compromise the integrity, confidentiality, and availability of the data managed by the software through standard network interaction.

Does this vulnerability require special authentication to trigger?

No. The vulnerability is triggered by sending specially crafted HTTP requests to the target system. Because the flaw allows for unauthenticated access, an attacker does not need to possess valid login credentials or prior permissions. It is important to note that internal network requests are sufficient to trigger the issue, so the risk is not limited to external traffic alone.

Why does Halo Surface Signal categorize this as only 'Possible'?

Halo Surface Signal labels this as 'Possible' because Oracle Coherence is primarily architected to serve as an internal-facing data grid or caching layer. While the vulnerability is technically reachable via HTTP, it is not a standard design choice to expose these services directly to the public internet. Therefore, the actual risk depends heavily on whether your specific deployment has mistakenly made these internal components accessible to wider networks.

How do I start addressing this issue in my environment?

Your first step is to perform an internal inventory to locate all instances of Oracle Coherence running in your infrastructure. Once identified, evaluate which applications rely on these instances and confirm their network accessibility. Work with the application and platform owners responsible for these systems to verify the impact and plan for necessary maintenance or security updates.

References