External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60251

Oracle Coherence is a distributed caching and data grid solution. While it is accessible via TCP, it is typically deployed in internal application tiers or backend environments to support middleware and enterprise applications rather than being directly exposed to the public internet by design.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by an unauthenticated attacker with network access, potentially leading to a complete takeover of the Coherence system. The severity score indicates significant impacts on confidentiality, integrity, and availability.

  • It's a critical flaw in Oracle Coherence.
  • High impact on data and systems.
  • Confirm relevance and exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker can target Oracle Coherence by sending malicious network requests over TCP. This vulnerability affects the core component and does not require any prior authentication. Successful exploitation could lead to a complete takeover of the Oracle Coherence system.

  • Network access required.
  • Unauthenticated TCP request triggers.
  • Full system takeover risk.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This vulnerability impacts the confidentiality, integrity, and availability of the affected Oracle Coherence environments.

  • Oracle Coherence system data at risk.
  • Unauthenticated network access allows exposure.
  • Complete system takeover is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Coherence requires immediate attention from teams managing Oracle Fusion Middleware. The first practical step is to identify all deployments of the affected product, determine their network accessibility and business criticality, and then locate the accountable system owner to plan a coordinated remediation effort.

  • Own by Oracle Fusion Middleware administrators.
  • Verify network exposure and critical assets.
  • Plan coordinated remediation with owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed caching and data grid solution used within Oracle Fusion Middleware. It provides high-speed access to frequently used data, helping applications scale by keeping information in memory across a cluster of servers rather than relying solely on a primary database.

How does CVE-2026-60251 impact Oracle Coherence?

This vulnerability represents a critical security weakness in the Core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely, which can lead to a full takeover of the Coherence system, granting the attacker control over its data, integrity, and operational availability.

Can any network request trigger this vulnerability?

Not every request triggers this flaw. Exploitation requires an unauthenticated attacker to have specific network access to the system via TCP. If the Coherence instance is not reachable over the network, or if access is restricted by firewalls or network segmentation, the ability for an attacker to initiate the malicious request is significantly hindered.

How do I know if my systems are at risk based on Halo Surface Signal?

Halo Surface Signal indicates that while Oracle Coherence is accessible via TCP, it is usually deployed in backend environments or internal application tiers. You should evaluate whether your Coherence instances are exposed to the public internet or remain restricted to internal networks, as this positioning dictates your level of immediate risk.

What is the first step to address this CVE?

The priority is to inventory your environment to locate all deployments of the affected Oracle Coherence versions. Once identified, work with the system owners to assess their specific network accessibility and business criticality, which will guide the urgency and planning of your patching or mitigation efforts.

References