External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60254

Oracle Coherence is a distributed data grid used for caching and data management. While it uses network protocols (TCP) and can be accessed remotely, it is typically deployed in back-end infrastructure, clustered environments, or internal application tiers rather than being directly exposed to the public internet by design.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component used in Oracle Fusion Middleware for data management and caching. This issue, which is easily exploitable by unauthenticated attackers over the network, could lead to a complete takeover of the affected Coherence instances, impacting confidentiality, integrity, and availability with a base score of 9.8. The main concern is confirming relevance and exposure within your environment.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • This impacts core data management and caching systems.
  • Confirm if Oracle Coherence is used in your environment.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending network requests to Oracle Coherence. Successful exploitation allows the attacker to gain complete control over the affected system.

  • Unauthenticated network access required.
  • Attacker sends network requests.
  • Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact the core functionality and data managed by Oracle Coherence. An unauthenticated attacker with network access could potentially exploit this to gain complete control over the Oracle Coherence system.

  • Oracle Coherence system and data at risk.
  • Unauthenticated network access could enable exposure.
  • Complete takeover of the Oracle Coherence system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence product is typically deployed in back-end infrastructure, clustered environments, or internal application tiers, suggesting that platform or infrastructure teams likely own this technology. The first practical step is to identify all Oracle Coherence instances, determine their network reachability and business criticality, and locate the accountable owner for each. This information will inform a risk-based remediation plan.

  • Platform/Infrastructure teams should own.
  • Verify network exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a specialized software component within Oracle Fusion Middleware designed for distributed data management and caching. It acts as a high-performance grid, allowing applications to store, manage, and process large amounts of data across multiple server nodes simultaneously. Organizations typically rely on it to speed up data access and ensure system scalability for complex, data-heavy enterprise applications.

What does CVE-2026-60254 mean for the software?

This vulnerability indicates a critical weakness in the Core component of Oracle Coherence. It allows an attacker to send unauthorized network commands to the software without needing any login credentials. Because the system fails to properly validate these incoming requests, the flaw can be leveraged to achieve a full takeover, granting an intruder complete control over the affected Coherence instance and the data it manages.

How is this vulnerability triggered?

An attacker triggers this bug by sending specific, malicious requests over TCP to an affected Oracle Coherence instance. This vulnerability requires direct network access to the component to succeed. Crucially, it is not triggered by standard user interactions through a web browser or application interface, but rather through lower-level network communication that the Coherence grid uses for its own internal operations.

Is my environment at risk from this CVE?

According to Halo Surface Signal, Oracle Coherence is generally deployed in internal application tiers or back-end infrastructure, not directly on the public internet. While the vulnerability is technically reachable via a network, your primary concern is identifying if any instances are inadvertently accessible from outside your secure perimeter. Most risk is concentrated on internal systems that might be exposed to broader corporate network segments.

What should I do if I run Oracle Coherence?

Your first step is to perform an inventory of all Oracle Coherence instances within your infrastructure. Once identified, evaluate which systems are reachable over the network and prioritize those that handle sensitive business functions. Coordinate with the platform or infrastructure teams responsible for these servers to confirm the specific version in use and track the official security updates provided by Oracle to address this flaw.

References