External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60272

Oracle Coherence is a data grid solution typically deployed in back-end infrastructure to support application clustering and caching. While this vulnerability is reachable via HTTP, the product is generally intended for internal network communication between application components rather than as a public-facing internet service.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, easily exploitable by unauthenticated attackers over a network, could allow for complete takeover of the Coherence system, impacting confidentiality, integrity, and availability. The main concern is confirming its relevance and exposure within our specific deployments.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • Affects a critical middleware component supporting applications.
  • Confirm relevance and potential exposure in our environment.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle Coherence by sending a specially crafted request over the network via HTTP. This would target the Core component of Oracle Coherence, potentially leading to a complete takeover of the system.

  • Attacker has network access.
  • Unauthenticated attacker triggers vulnerability.
  • Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to take over Oracle Coherence. This could impact the confidentiality, integrity, and availability of the service when deployed in supported versions.

  • Oracle Coherence service.
  • Network access via HTTP.
  • Takeover of the Coherence service.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Oracle Fusion Middleware, including application owners and infrastructure or platform teams, must identify all deployments of Oracle Coherence. Confirming network reachability, business criticality, and the accountable owner is the critical first step before planning remediation or implementing temporary risk reduction measures.

  • Application and platform teams own the issue.
  • Verify Coherence network exposure and criticality.
  • Plan and coordinate vendor-supported remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution. It acts as a distributed cache and data management layer that helps applications scale by clustering servers together to share data efficiently. It is a core piece of Oracle Fusion Middleware used primarily in back-end environments to handle high-volume data processing and application state synchronization.

How does CVE-2026-60272 affect Oracle Coherence?

This CVE represents a critical security flaw in the Coherence Core component. It functions as a serious software defect that permits an attacker to bypass authentication entirely. By successfully sending a crafted HTTP request, an unauthorized user can gain complete control over the Coherence instance, effectively compromising its ability to protect data and maintain service operations.

What triggers this vulnerability?

The vulnerability is triggered when an attacker with network access sends a specially crafted HTTP request to the Oracle Coherence service. It does not require any prior user authentication or administrative credentials to execute. Notably, this flaw is specific to the handling of incoming requests; simply running the software in an isolated environment without network exposure to untrusted parties prevents the attack from being initiated.

Do I need to worry if my Coherence instance is internal?

According to Halo Surface Signal, Oracle Coherence is typically deployed in back-end infrastructure for internal communication between application components rather than as a public-facing service. While the risk is technically lower for internal systems, any network reachability via HTTP—even within your internal environment—means an attacker who has already breached your perimeter could potentially target this system.

What should I do first to address this CVE?

Your first step is to perform an inventory of all Oracle Coherence deployments within your organization. Identify the specific versions in use to see if they match the affected releases. Once identified, map out which instances are reachable over the network and verify their business criticality. This provides the necessary foundation for your team to prioritize and coordinate the installation of official vendor-supplied security patches.

References