External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60257

Oracle Coherence is a data grid solution typically deployed in internal application tiers to support backend services. While it requires network access, it is generally architected to be isolated from the public internet, though it may be exposed in some specific, misconfigured, or unusual cloud-native deployments.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, allows for easy exploitation by unauthenticated attackers over the network. This could lead to a complete takeover of the Coherence environment, impacting confidentiality, integrity, and availability. While typically deployed internally, its exposure needs to be confirmed, especially in cloud-native environments.

  • Unauthenticated attackers can take over Oracle Coherence.
  • Confirm relevance and exposure of this critical product.
  • Assess impact and prioritize protection of Coherence.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network traffic to an exposed Oracle Coherence instance. Because the vulnerability is exploitable without authentication, an attacker with network access can directly interact with the vulnerable component. Successful exploitation allows an attacker to gain complete control over the Oracle Coherence system.

  • Attacker needs network access.
  • Unauthenticated network request triggers vulnerability.
  • Attacker can fully take over the system.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Coherence could allow an unauthenticated attacker with network access to take over the entire Oracle Coherence system, potentially impacting the confidentiality, integrity, and availability of the data and services it manages.

  • Oracle Coherence system is at risk.
  • Unauthenticated network access could lead to compromise.
  • Full system takeover is a realistic consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence, a data grid solution, primarily impacts application owners and potentially platform teams responsible for its deployment and operation. The first critical step is to identify all instances of Oracle Coherence within your environment, confirm their business criticality and network exposure, and then engage with the accountable owners to plan a risk-based remediation strategy.

  • Application owners should take ownership.
  • Verify network reachability and business criticality.
  • Plan remediation based on exposure and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution within Oracle Fusion Middleware. It provides distributed caching and data management to help applications handle large volumes of data and state information across clustered servers, ensuring high performance and reliability for backend services.

What does CVE-2026-60257 mean for system security?

This vulnerability is a critical security flaw in the Oracle Coherence core. It allows an attacker to gain unauthorized control over the software. Because it involves a complete system takeover, it compromises the confidentiality, integrity, and availability of the data and services that the data grid manages.

How does an attacker trigger this vulnerability?

An attacker triggers this bug by sending specially crafted network traffic directly to the Oracle Coherence component. It does not require any user credentials or login to perform the attack. However, the attacker must have direct network access to the target instance to initiate the request.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, this software is typically deployed within internal application tiers, which provides a layer of isolation. However, if your specific setup is misconfigured or utilizes an unusual cloud-native deployment that leaves the instance reachable from the public internet, the risk level increases significantly.

What should I do first to address this CVE?

Start by identifying all Oracle Coherence instances running in your environment. Once identified, verify their current network accessibility and overall business criticality. This information will help you and your platform teams prioritize which systems require immediate attention and remediation.

References