External risk intelligence

Oracle Coherence Unauthenticated Network Takeover Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60275

Oracle Coherence is a data grid solution typically deployed within internal application tiers, middle-tier clusters, or backend infrastructures. While the vulnerability is reachable via HTTP, this product is generally not designed as a public-facing edge service, though it may be exposed to the internet in certain misconfigured or specific enterprise architecture deployments.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue could allow an unauthenticated attacker with network access to fully compromise the Oracle Coherence system, potentially leading to significant impacts on confidentiality, integrity, and availability. The primary concern is confirming whether our environment utilizes this technology and is exposed.

  • Unauthenticated attackers can take over Oracle Coherence.
  • Leadership should be aware of potential system compromise.
  • Confirm relevance and exposure to Oracle Coherence.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending network requests over HTTP to a vulnerable Oracle Coherence component. Successful exploitation could allow an attacker to gain complete control over the Oracle Coherence system.

  • No authentication required.
  • Triggered via network access over HTTP.
  • Full system takeover possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of data and services managed by Oracle Coherence.

  • Oracle Coherence system data.
  • Network access over HTTP.
  • Complete takeover of the service.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determine ownership by identifying the application or platform teams managing Oracle Coherence, as they are most likely responsible for this component. The first practical step involves locating all instances of Oracle Coherence within your environment, assessing their exposure and business criticality, and then identifying the accountable owner to collaboratively plan remediation based on the associated risk.

  • Application or platform teams own resolution.
  • Verify Coherence instance exposure and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution used to provide fast access to frequently used data. It acts as an in-memory storage layer for large-scale applications, helping them manage and process data rapidly across distributed clusters within a middleware environment.

What does CVE-2026-60275 mean?

This CVE represents a critical security weakness that allows an unauthorized person to gain full control over the Oracle Coherence system. Because the vulnerability involves no authentication, it effectively allows an attacker to bypass security checks and manipulate the software directly.

How is this vulnerability triggered?

The vulnerability is triggered when an attacker sends specifically crafted requests over HTTP to an affected system. It is important to note that actions performed through non-HTTP protocols or internal management channels that do not involve this specific HTTP interface would not trigger this vulnerability.

Is my Oracle Coherence installation at risk?

According to Halo Surface Signal, this software is typically found in internal backend tiers rather than on the public edge. While it is rarely meant to be internet-facing, your risk level depends on whether your specific deployment has been misconfigured to allow direct network access from untrusted sources.

What should I do to secure my systems?

Start by identifying all instances of Oracle Coherence in your environment and determining which teams manage them. Once you have located these assets, assess their specific network exposure and business importance to prioritize them for updates as directed by the official security guidance.

References