External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60262

Oracle Coherence is a data grid solution typically deployed within internal application tiers to support backend data caching and clustering. While it relies on network communication and could be exposed if misconfigured or improperly segmented, it is not designed to be a public-facing internet service or edge gateway in standard architectural deployments.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue allows for easy exploitation by unauthorized attackers over the network, potentially leading to a complete takeover of the Coherence system. The severity of this vulnerability, with a high CVSS score, indicates significant potential impacts on confidentiality, integrity, and availability.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • Remember this for potential internal system risks.
  • Confirm if Coherence is deployed and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending network requests over TCP, without needing any prior authentication. This can lead to a full takeover of the Coherence system.

  • No authentication required.
  • Network access via TCP.
  • Full system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of the data managed by Oracle Coherence.

  • Oracle Coherence system data.
  • Network access to the system.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining ownership requires understanding where Oracle Coherence is deployed within your environment. Typically, application owners or platform teams would manage this component, especially if it's integral to business-critical applications. The first practical step is to locate all instances of Oracle Coherence, assess their exposure and criticality, and then confirm the accountable team for remediation.

  • Application or platform teams own the issue.
  • Verify Coherence deployment and exposure.
  • Plan remediation based on criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid used within Oracle Fusion Middleware. It provides distributed caching and clustering capabilities, allowing applications to store and process large amounts of data across multiple servers to improve performance and scalability.

What does CVE-2026-60262 mean for the system?

This vulnerability is a critical security flaw that lacks a specific weakness classification in current records. In plain terms, it permits an attacker to bypass security controls and gain full control over the Coherence software without providing any login credentials, effectively granting them the same authority as a legitimate administrator.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specific network requests over TCP directly to the affected Oracle Coherence component. It does not require any user interaction or prior authentication. Note that only systems reachable via the network are susceptible; local actions or services that are completely isolated from network traffic are not paths for this specific bug.

Is my Oracle Coherence deployment at risk?

Halo Surface Signal identifies Oracle Coherence as typically deployed in internal application tiers for backend caching, rather than as a public-facing service. However, if your specific architecture misconfigures or fails to segment these systems, they could become accessible to unauthorized network traffic, increasing your risk profile.

What should I do if I run Oracle Coherence?

Begin by auditing your infrastructure to locate all instances of Oracle Coherence across your environment. Once identified, work with the platform or application teams responsible for those specific instances to confirm their network exposure level and evaluate their role in business-critical operations to prioritize remediation planning.

References