External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60247

Oracle Coherence is a distributed caching and data grid solution typically deployed within internal network tiers to support backend applications. While the vulnerability is reachable via HTTP and does not require authentication, it is not a standard internet-facing gateway or edge service by design, making public exposure less common than typical web applications.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware. The issue is easily exploitable by unauthenticated attackers over HTTP, potentially leading to a complete takeover of the Coherence system. The high CVSS score of 9.8 indicates significant impacts on confidentiality, integrity, and availability.

  • Unauthenticated attackers can fully control Coherence.
  • Criticality requires verifying if Coherence is in use.
  • Confirm relevance and exposure of this Oracle component.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access can exploit this vulnerability by sending a request over HTTP to Oracle Coherence. Successful exploitation could lead to a complete takeover of the Coherence system, impacting confidentiality, integrity, and availability.

  • Network access is required.
  • Attacker triggers vulnerability via HTTP.
  • Complete system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could potentially compromise Oracle Coherence, leading to a full takeover of the system. This could affect the confidentiality, integrity, and availability of the data managed by Oracle Coherence when supported.

  • Oracle Coherence system.
  • Network-based access via HTTP.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a real-world scenario, teams responsible for Oracle Fusion Middleware, including application owners and infrastructure or platform teams, should address this vulnerability in Oracle Coherence. The initial focus must be on identifying all instances of the affected product, assessing their network exposure and business criticality, and locating the accountable system owner to plan a risk-based remediation strategy.

  • Identify accountable system owners.
  • Verify network reachability and criticality.
  • Plan coordinated vendor remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed caching and data grid component within Oracle Fusion Middleware. It provides high-speed, scalable data storage and processing for enterprise applications, allowing them to manage shared data across multiple servers effectively.

What does CVE-2026-60247 mean for the software?

This vulnerability indicates a critical weakness in the Core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms to gain unauthorized control over the software, which can lead to a total compromise of the system's data and operations.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specifically crafted request over HTTP to the Oracle Coherence instance. This does not require local user interaction or prior credentials. The vulnerability is not triggered by actions occurring solely within local non-networked processes; it specifically requires reachable network access to the Coherence service.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is typically used for internal backend data grids rather than being exposed directly on the public internet. While it is not usually a standard edge service, any instance with reachable HTTP network access is considered potentially vulnerable to unauthorized remote commands.

What steps should I take if I use Oracle Coherence?

First, inventory your environment to confirm where Oracle Coherence 12.2.1.4.0 or 14.1.1.0.0 is deployed. Once identified, evaluate the network reachability of these systems to determine if they are accessible over HTTP. Engage the system owners to prioritize and plan for the vendor-provided updates necessary to secure the affected infrastructure.

References