External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60276

Oracle Coherence is a data grid and caching layer typically deployed in back-end environments rather than directly exposed to the public internet. While the vulnerability is reachable over HTTPS, such services are generally protected behind firewalls or internal network segments, making direct public-facing exposure less common than dedicated edge services.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, which is easily exploitable by unauthenticated attackers over HTTPS, could lead to a complete takeover of the Coherence system, potentially impacting data confidentiality, integrity, and availability. The main concern is confirming its relevance and exposure within our specific environment.

  • Unauthenticated attackers can fully control Coherence.
  • Understand if our Coherence systems are at risk.
  • Confirm exposure and relevance to our business.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending network requests over HTTPS, without needing any prior authentication. This vulnerability targets the Core component of Oracle Coherence and can lead to a full takeover of the system.

  • Unauthenticated network access required.
  • Exploits the Core component.
  • Results in system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access to Oracle Coherence, typically used as a data grid and caching layer, could potentially achieve full control over the system. This could affect the confidentiality, integrity, and availability of the data managed by Oracle Coherence under supported conditions.

  • System data and services at risk.
  • Attacker with network access exploits it.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Coherence likely impacts application owners and platform teams responsible for managing Oracle Fusion Middleware deployments. The initial step is to identify all instances of Oracle Coherence within the environment, confirm their network accessibility, and determine their business criticality. Once these instances are inventoried and prioritized, the accountable owner can be identified to plan and execute remediation, potentially involving vendor coordination or temporary risk reduction measures.

  • Platform and Application Owners should lead remediation.
  • Verify Oracle Coherence instances and exposure.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a specialized software component within Oracle Fusion Middleware that functions as an in-memory data grid and caching layer. It is used by large-scale enterprise applications to manage, store, and provide rapid access to high volumes of frequently used data across distributed computing environments.

What does CVE-2026-60276 mean for the system?

This vulnerability represents a critical security flaw in the core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely, potentially gaining unauthorized control over the software. Because it impacts the system's core, a successful attack could compromise the confidentiality, integrity, and availability of all data managed by the platform.

How does an attacker trigger this vulnerability?

An attacker triggers this vulnerability by sending specially crafted network requests to the target system over HTTPS. It does not require the attacker to have valid user credentials or prior access to the system. However, the attack requires the service to be reachable; internal-only components that are not accessible via the network cannot be reached through this path.

Is my Oracle Coherence instance at risk?

Per Halo Surface Signal, Oracle Coherence is typically used in back-end environments rather than being exposed directly to the public internet. While the vulnerability is reachable over HTTPS, instances hidden behind firewalls or restricted to internal network segments are significantly less likely to face direct, opportunistic exploitation than services facing the public web.

What should I do if I run Oracle Coherence?

Your first step is to perform a complete inventory of all Oracle Coherence instances within your infrastructure to identify which versions are in use. Once identified, evaluate the network accessibility of each instance to determine which are reachable over HTTPS. Prioritize these systems for patching or applying vendor-recommended security updates to mitigate the risk of unauthorized takeover.

References