External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60256

Oracle Coherence is a data grid solution typically deployed within internal application tiers, service clusters, or backend middleware layers. While the vulnerability is reachable over a network, it is not a standard internet-facing gateway or public-facing service in common deployment patterns, making public exposure via the internet less common than internal network accessibility.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue, rated with a CVSS score of 9.8, is easily exploitable by an unauthenticated attacker with network access, potentially leading to a complete takeover of the affected Coherence environment. The main concern at this time is confirming the relevance and exposure of this vulnerability within our environment.

  • Unauthenticated network access can fully compromise Coherence.
  • This is a critical vulnerability with high impact.
  • Confirm relevance and exposure in our environment.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle Coherence by sending network requests to an exposed TCP endpoint. This vulnerability allows an unauthenticated attacker to gain complete control over the Coherence system.

  • Attacker needs network access.
  • Triggered via TCP connection.
  • Results in full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to completely compromise the Oracle Coherence system. Successful exploitation could lead to a full takeover of the affected Coherence environment, impacting its confidentiality, integrity, and availability.

  • Oracle Coherence system.
  • Network access via TCP.
  • Takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Oracle Coherence, likely managed by application owners or platform teams responsible for Oracle Fusion Middleware. The immediate first step is to discover all instances of Oracle Coherence, determine their network exposure and business criticality, and identify the accountable owner for each. Subsequently, a risk-based remediation plan can be developed, potentially involving coordination with Oracle for fixes or implementing compensating controls.

  • Application or Platform Owners should own.
  • Verify network reachability and criticality.
  • Plan remediation based on verified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution within Oracle Fusion Middleware. It provides distributed caching and data management, allowing applications to store and process data in-memory across a cluster of servers. It is commonly used as a backend component to improve performance and scalability for enterprise applications.

How does CVE-2026-60256 affect software security?

This vulnerability represents a significant security weakness in the Core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely. Because it affects the core functionality of the system, a successful attack could grant an unauthorized party full control over the affected Oracle Coherence instance, compromising data confidentiality, integrity, and availability.

What triggers this Oracle Coherence vulnerability?

The vulnerability is triggered when an attacker establishes a network connection to an Oracle Coherence instance via TCP. It does not require any prior authentication or user interaction to succeed. Notably, the vulnerability is not triggered by standard application-layer logic or authorized API calls, but rather by malformed or unauthorized network requests directed at the Coherence service port.

Why should I worry about CVE-2026-60256?

According to Halo Surface Signal, Oracle Coherence is typically used in internal middleware layers rather than as a public gateway. While the vulnerability requires only network access, its severity depends on whether your instances are reachable from untrusted networks. You should care if your Coherence clusters are accessible from broader internal segments where an attacker might have gained a foothold.

What should I do if I run Oracle Coherence?

Begin by identifying all running instances of Oracle Coherence within your infrastructure and determining who is responsible for each. Verify the current network configuration to see if these instances are exposed to broader network segments. Once mapped, assess the business criticality of those specific clusters to prioritize your risk management and coordinate with platform teams for security updates.

References