External risk intelligence

Oracle Coherence Core Unauthorized Data Manipulation and Access Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-60267

Oracle Coherence is a data grid solution typically deployed in backend or internal infrastructure to support application clustering and data caching. While it requires network access and the vulnerability is reachable over the network, it is not architecturally designed to be a public-facing edge service, web app, or gateway in standard deployments.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by unauthenticated attackers over the network, potentially leading to unauthorized access, modification, or deletion of critical data. The primary concern is to confirm if Oracle Coherence is deployed within your environment and assess any potential exposure.

  • Unauthorized access to critical Coherence data.
  • Confirm relevance and exposure in your environment.
  • Understand data access and modification risks.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Coherence by sending network requests over TLS. Because the vulnerability is easily exploitable and requires no authentication, an attacker could gain unauthorized access to critical data, modify it, or gain complete access to all accessible data within Oracle Coherence.

  • Unauthenticated network access required.
  • Vulnerability triggered via network requests.
  • Risk of unauthorized data access or modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact the integrity and confidentiality of data within Oracle Coherence when accessed over TLS. An unauthenticated attacker could gain unauthorized access to critical data or modify or delete data.

  • Critical data in Oracle Coherence.
  • Attacker exploits network access via TLS.
  • Unauthorized data creation, deletion, modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a typical Oracle Coherence deployment, responsibility for addressing this vulnerability likely falls to infrastructure, platform, or database administration teams, possibly in coordination with application owners and vendor management. The first practical step is to identify all instances of Oracle Coherence, confirm their network accessibility and business criticality, and then assign ownership for remediation planning based on risk.

  • Platform or infrastructure teams should own the issue.
  • Verify Coherence network exposure and criticality.
  • Plan remediation considering vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used to manage, cache, and distribute data across clustered environments. It is a core component of Oracle Fusion Middleware, typically utilized by enterprises to boost application performance and scalability by keeping frequently accessed information accessible in high-speed memory.

What does CVE-2026-60267 mean for data security?

This vulnerability represents a significant flaw in the Core component that allows an unauthenticated user to interact with the data grid remotely. Because it lacks proper access controls, an attacker can bypass security requirements to view, change, or destroy sensitive information stored within the system, effectively compromising the confidentiality and integrity of the managed data.

How is this vulnerability triggered?

An attacker triggers this flaw by sending specially crafted network requests over a TLS connection to the affected Oracle Coherence instance. Importantly, this does not require any valid user credentials or login privileges. However, the flaw cannot be exploited without network-level reach to the specific port used by the Coherence cluster.

Is my Oracle Coherence instance at risk?

Per Halo Surface Signal, Oracle Coherence is generally deployed in backend or internal infrastructure to support data caching and is not typically designed as a public-facing edge service. While the vulnerability is reachable over a network, instances buried deep within internal networks are safer than those mistakenly exposed to broader network segments or the internet.

How do I respond to this threat?

Your first step is to perform an inventory of your environment to locate all running instances of the affected Oracle Coherence versions. Once identified, confirm the network accessibility and business sensitivity of these systems. Coordinate with your infrastructure or platform administration teams to prioritize remediation and monitor official vendor updates to address the underlying software defect.

References