External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60246

Oracle Coherence is a middleware product typically deployed within internal application tiers to manage distributed cache and data grids. While it uses network protocols for clustering and communication, it is not designed to be directly exposed to the public internet in standard deployments, making internet-facing exposure uncommon despite the network-accessible nature of the vulnerability.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Oracle Coherence, a middleware product, allows unauthenticated attackers to potentially take over the system remotely. This issue could impact data integrity and availability, depending on how Oracle Coherence is integrated within our environment.

  • Unauthenticated remote takeover of Oracle Coherence.
  • Critical flaw with high impact on Confidentiality, Integrity, Availability.
  • Confirming relevance and exposure is the main concern.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending specially crafted network traffic over TCP. This is possible because the vulnerability is easily exploitable and requires no authentication. Successful attacks can lead to a complete takeover of the affected Oracle Coherence system.

  • No authentication needed.
  • Network access via TCP.
  • System takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could compromise Oracle Coherence when it's exposed via TCP. Successful exploitation could lead to a complete takeover of the affected Oracle Coherence system, impacting its confidentiality, integrity, and availability.

  • Oracle Coherence system data at risk.
  • Network access via TCP could expose.
  • Takeover of Oracle Coherence service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence, an Oracle Fusion Middleware product, likely impacts platform or application teams responsible for its management and operation. The initial step should be to identify all Oracle Coherence deployments, assess their network reachability and criticality, identify the accountable owners, and then plan remediation based on the risk assessment.

  • Platform/Application owners should take ownership.
  • Verify Oracle Coherence deployment reachability and criticality.
  • Plan risk-based remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a middleware component within Oracle Fusion Middleware designed for distributed caching and data grid management. It enables high-performance data processing and storage across clustered environments, supporting versions 12.2.1.4.0 through 15.1.1.0.0.

What is the nature of CVE-2026-60246?

This vulnerability is a critical flaw in the Oracle Coherence Core component. It lacks authentication, which allows unauthorized parties to compromise the system. It is classified as easily exploitable with high impacts on confidentiality, integrity, and availability.

How can an attacker trigger this vulnerability?

An attacker can initiate a system takeover by sending specifically crafted network traffic over TCP. The vulnerability does not require authentication or user interaction to facilitate unauthorized control, provided the service is reachable via the network.

Is this vulnerability relevant to my environment?

While the flaw allows network-based access, Halo Surface Signal indicates that Oracle Coherence is typically deployed in internal tiers and is not intended for public internet exposure. Therefore, direct internet-facing exposure remains uncommon.

How should teams respond to this vulnerability?

Owners should first identify all active Oracle Coherence deployments and verify their network reachability. Once reachability and criticality are assessed, teams must coordinate with the vendor to plan and implement risk-based remediation strategies.

References