External risk intelligence

Oracle Coherence Core Remote Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60289

Oracle Coherence is a data grid and caching layer typically deployed within internal application tiers to support backend services. While the vulnerability is reachable via HTTP, this product is generally not intended to be directly exposed to the public internet, though it may be accessible in some misconfigured or specific enterprise integration scenarios.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, allows unauthenticated attackers to potentially take control of the system over the network. This issue impacts core functionality and could have significant consequences if exploited. The primary concern is confirming whether this technology is deployed and accessible within your environment.

  • Unauthenticated network access can seize control.
  • Verify if this Oracle product is in use.
  • Assess potential impact on core services.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending malicious requests over the network to the Oracle Coherence product. No authentication is required, and the vulnerability can lead to a complete takeover of the affected system.

  • Attacker needs network access.
  • Malicious network requests trigger it.
  • Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Coherence could allow an unauthenticated attacker with network access via HTTP to completely take over the affected Oracle Coherence system. Such a compromise could lead to a significant impact on data confidentiality, integrity, and availability, depending on how the affected system is configured and utilized.

  • Oracle Coherence system data and behavior.
  • Unauthenticated network access via HTTP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Coherence is typically an internal component, suggesting platform or application teams manage its ownership. The first step is to identify all instances of Oracle Coherence, determine their network accessibility and business criticality, and then confirm the accountable owner before planning remediation.

  • Platform or application teams own the issue.
  • Verify network reachability and criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a specialized in-memory data grid and caching solution within the Oracle Fusion Middleware suite. It is designed to help applications handle high volumes of data by distributing it across multiple servers, providing fast access to critical information for complex, backend business services.

What does the CVE-2026-60289 vulnerability allow?

This flaw allows an unauthenticated attacker to send malicious HTTP requests to the system. By leveraging this weakness, an unauthorized individual could potentially seize complete control of the Oracle Coherence environment, which would compromise the confidentiality, integrity, and availability of the data and services it manages.

How is this vulnerability triggered?

The vulnerability is triggered when an attacker sends specific, malicious HTTP requests over the network to a reachable Oracle Coherence instance. Importantly, this does not require the attacker to have valid login credentials or prior access to the system. It is not triggered by standard, legitimate application traffic that complies with expected system operations.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is generally deployed within internal application tiers, meaning it should not be directly exposed to the public internet. However, your risk level increases if your specific environment has misconfigured settings or unique enterprise integrations that make the system reachable via HTTP from broader networks.

What should I do if I use Oracle Coherence?

Start by identifying all instances of Oracle Coherence across your infrastructure to determine which teams are responsible for their maintenance. Assess the network reachability and business criticality of each instance. Once you have a clear inventory, work with the appropriate platform or application owners to prioritize these systems for remediation.

References