External risk intelligence

Oracle Coherence Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60258

Oracle Coherence is a data grid solution typically deployed within internal application tiers, backend clusters, or middleware environments. While it uses TCP networking and can be exposed, it is generally not designed to be directly internet-facing in standard deployment patterns.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue allows an unauthenticated attacker with network access to potentially take over the system, impacting confidentiality, integrity, and availability with a high severity score. Given that Oracle Coherence is typically an internal component, the main concern is to confirm if it is relevant and exposed within our environment.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • Matters because it could compromise internal critical systems.
  • Confirm if this internal technology is exposed.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access could potentially exploit a vulnerability in Oracle Coherence. By leveraging this vulnerability, an attacker could gain complete control over the Oracle Coherence system.

  • Network access via TCP.
  • Unauthenticated access to a vulnerable component.
  • Takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could potentially take over Oracle Coherence. This could affect the confidentiality, integrity, and availability of the system and any data it manages.

  • System data and service behavior.
  • Network access to TCP.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Oracle Fusion Middleware, specifically Oracle Coherence, should lead the response. This often involves application owners, infrastructure teams, and potentially the vendor-management team if support contracts are in place. The immediate priority is to pinpoint all instances of the affected Oracle Coherence, determine their exposure and criticality, and identify the accountable system owner before planning remediation.

  • Identify Oracle Coherence instances and ownership.
  • Verify network reachability and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed data grid solution that acts as a caching and data management layer. It is used in enterprise environments to enable fast, reliable access to frequently used data across clustered applications, forming a core part of Oracle Fusion Middleware.

What does the CVE-2026-60258 vulnerability mean?

This vulnerability is a flaw in the core component of Oracle Coherence that allows a remote attacker to gain unauthorized control over the software. It represents a significant weakness where the system fails to properly validate requests, enabling an unauthenticated user to effectively take over the affected service.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending malicious commands directly to the Oracle Coherence component over a network connection using the TCP protocol. This vulnerability does not require the attacker to have valid user credentials, but it cannot be triggered without direct network reachability to the Coherence service.

Is my environment at risk from CVE-2026-60258?

Halo Surface Signal indicates that while Oracle Coherence uses TCP networking, it is typically deployed in internal backend tiers. You are at higher risk if your configuration accidentally exposes these internal services to the broader internet. Reviewing your network boundaries is the primary way to determine if this is reachable by untrusted actors.

What should I do if I run Oracle Coherence?

Start by identifying every instance of Oracle Coherence in your environment and confirming who owns them. Verify the network accessibility of these instances to understand if they are truly internal or improperly exposed. Once mapped, coordinate with your infrastructure and application teams to prepare for vendor-supplied updates.

References