External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60244

Oracle Coherence is a middleware component frequently exposed to network traffic for distributed application communication. Since this vulnerability is exploitable via HTTP by an unauthenticated attacker with network access, the likelihood of exposure is significant for environments where these management or data caching interfaces are reachable.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue is easily exploitable by an unauthenticated attacker with network access, potentially leading to a complete takeover of the Coherence environment and impacting confidentiality, integrity, and availability.

  • Unauthenticated network access can fully compromise Oracle Coherence.
  • Leadership should remember this for potential system control risks.
  • Confirm relevance and exposure of Oracle Coherence deployments.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle Coherence by sending network requests over HTTP. No special access or authentication is needed to reach this vulnerable component. Successful attacks could lead to full control over the Coherence system, impacting its confidentiality, integrity, and availability.

  • Attacker needs network access.
  • Vulnerable component is Core.
  • Attacker can take over Coherence.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of the Oracle Coherence service.

  • Oracle Coherence service is at risk.
  • Network access via HTTP allows exposure.
  • Successful attacks could lead to system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Oracle Coherence, such as application owners, infrastructure teams, and platform teams, should lead the response to this critical vulnerability. The immediate priority is to identify all instances of affected Oracle Coherence deployments, determine their reachability and business criticality, and confirm the accountable owner for each. This information will inform a risk-based remediation plan, potentially involving vendor coordination or temporary mitigations.

  • Owner: Application and platform teams.
  • Verify: Network exposure and business criticality.
  • Action: Plan and execute risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a middleware component within Oracle Fusion Middleware designed for data caching and distributed application management. It helps large-scale applications handle high volumes of data efficiently by keeping information in memory, making it a critical foundation for performance in enterprise systems.

How does CVE-2026-60244 affect software security?

This vulnerability indicates a serious flaw in the Oracle Coherence Core component. It represents a weakness that allows an unauthorized user to bypass security controls. Because the flaw permits complete system takeover, it compromises the confidentiality, integrity, and availability of the data and services managed by the software.

What is required to trigger this vulnerability?

An attacker needs network access to the target system to send specially crafted HTTP requests. The vulnerability does not require the attacker to have a valid user account or password. It is important to note that local access or physical presence is not required; the exploit relies entirely on reachability over a network.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, this vulnerability is most relevant if your Coherence interfaces are reachable over the network. Because the service often handles distributed application communication, any instance exposed to untrusted network traffic faces a significant risk. Internal-only systems that are strictly segmented may face lower immediate risk than those exposed to broader network segments.

How should I begin addressing this CVE?

The first step is to locate all deployments of Oracle Coherence versions 12.2.1.4.0 and 14.1.1.0.0 within your environment. Once identified, evaluate which instances are accessible via the network. Coordinate with your application and platform teams to prioritize these systems, confirm ownership, and establish a plan to apply the necessary vendor-provided updates.

References