External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60286

Oracle Coherence is typically used as an internal-facing data grid or cache layer within middleware environments. While the vulnerability is reachable via HTTP, this service is generally deployed within protected backend infrastructure rather than as a public-facing edge service or gateway.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware, that could allow an unauthenticated attacker to take control of the system. This issue has a high severity score, indicating significant potential impact on confidentiality, integrity, and availability. The primary concern at this time is to confirm whether Oracle Coherence is in use within our environment and assess any potential exposure.

  • Unauthenticated attackers can gain full control.
  • Critical system compromise impacts data and operations.
  • Confirm Oracle Coherence usage and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach Oracle Coherence remotely via HTTP without needing to authenticate. Once network access is established, the attacker can target the Core component of Oracle Coherence. Successful exploitation of this vulnerability can lead to a complete takeover of the Coherence system.

  • Unauthenticated network access via HTTP required.
  • Target the Core component of Oracle Coherence.
  • Results in takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise Oracle Coherence, potentially leading to a complete takeover of the affected system. This could impact the confidentiality, integrity, and availability of the Coherence service.

  • Oracle Coherence system data at risk.
  • Unauthenticated network access via HTTP.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence could allow an unauthenticated attacker with network access to compromise the product, potentially leading to a full takeover. Infrastructure or platform teams responsible for managing Oracle Fusion Middleware deployments should take the lead in addressing this. The first practical move is to identify all instances of affected Oracle Coherence, determine their exposure and business criticality, and then engage the accountable application or system owner to plan a coordinated response.

  • Infrastructure and platform teams own this.
  • Verify network exposure and business criticality.
  • Plan coordinated response with application owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used within Oracle Fusion Middleware. It provides distributed caching and data management, allowing applications to store and access massive amounts of data rapidly across clustered servers to improve performance and scalability.

How does CVE-2026-60286 affect the system?

This vulnerability impacts the Core component of Oracle Coherence. It is a critical flaw that allows an unauthorized person to bypass security controls. Because the system fails to verify the identity of the requester, an attacker can gain full control over the affected Oracle Coherence instance.

What is required to trigger this vulnerability?

An attacker needs network access to the target via HTTP to reach the Coherence service. Crucially, the vulnerability does not require the attacker to have valid login credentials. It cannot be triggered if there is no network path from the attacker to the Coherence HTTP endpoint.

Is my environment at risk from this vulnerability?

According to Halo Surface Signal, Oracle Coherence is typically deployed as an internal-facing data grid. While the vulnerability is reachable over HTTP, it is generally protected within backend infrastructure rather than exposed as a public-facing service. You are at higher risk if your specific deployment allows unauthorized network traffic to reach these internal components.

How should I respond to CVE-2026-60286?

Start by identifying all instances of Oracle Coherence running in your environment. Confirm which versions are in use and determine if they are reachable over the network. Once you have an inventory, coordinate with the application owners responsible for those systems to review security configurations and plan necessary updates.

References