External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60259

Oracle Coherence is typically used in internal, backend, or distributed infrastructure. While this vulnerability is exploitable via HTTP without authentication, such middleware is rarely exposed directly to the public internet. It remains plausibly reachable only in cases of misconfiguration or specific architectural choices.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, which is easily exploitable by an unauthenticated attacker over the network, could lead to a complete takeover of the affected system. The potential impact on confidentiality, integrity, and availability is severe.

  • Unauthenticated attackers can fully control Coherence.
  • It could impact critical backend systems.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network requests to an exposed Oracle Coherence service. Since no authentication is required, an attacker on the network can directly interact with the vulnerable component, leading to a complete takeover of the Coherence system.

  • Unauthenticated network access required.
  • HTTP requests trigger the vulnerability.
  • Risk of full system takeover.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in Oracle Coherence could allow an unauthenticated attacker with network access via HTTP to completely take over the system. This means an attacker could potentially control the affected Oracle Coherence instances, impacting confidentiality, integrity, and availability.

  • Oracle Coherence system.
  • Unauthenticated network access via HTTP.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Coherence, a component of Oracle Fusion Middleware, is the affected technology. Responsibility for addressing this critical vulnerability likely falls to application owners or platform teams managing the Coherence deployments, with support from infrastructure and network/security teams for external exposure review. The initial step is to identify all Coherence instances, confirm their network reachability and business criticality, then assign an accountable owner to plan remediation based on the assessed risk.

  • Application or platform teams own the issue.
  • Verify Coherence instance exposure and criticality.
  • Plan remediation based on risk and business impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed caching and data grid solution within Oracle Fusion Middleware. It enables applications to store and manage data across multiple servers, ensuring high availability and performance. Organizations typically use it as a backend component to support large-scale, enterprise-level systems by providing fast, reliable data access for complex, high-transaction applications.

What does CVE-2026-60259 mean for the system?

This vulnerability represents a critical flaw in the core component of Oracle Coherence. It allows an attacker to bypass authentication requirements completely. By sending malicious data, an unauthorized user can gain total control over the affected system, potentially compromising the confidentiality, integrity, and availability of all data managed by that instance.

How is this vulnerability triggered?

The flaw is triggered when an attacker sends specially crafted HTTP requests to the Oracle Coherence service. Because the system does not require authentication to process these requests, any network-connected entity can attempt to exploit it. Actions that do not involve sending network traffic, such as local file management or unrelated application processing, do not trigger this specific vulnerability.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is generally deployed in internal, backend, or distributed infrastructure rather than directly on the public internet. While the vulnerability is highly dangerous, it is typically only reachable if your specific architecture or a misconfiguration has inadvertently exposed the service to broader network access.

How do I start addressing this CVE?

Begin by auditing your infrastructure to locate all active Oracle Coherence instances and determine their specific network reachability. Once identified, evaluate their criticality to your operations. Coordinate with your platform or application teams to establish ownership and create a plan to apply the necessary security updates provided by the vendor.

References