External risk intelligence

Oracle Coherence Core Vulnerability Allows Unauthenticated Network Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60290

Oracle Coherence is a data grid product typically deployed in internal enterprise application tiers. While the vulnerability is reachable via HTTP, these components are generally intended for backend use and are not commonly deployed as public-facing internet services.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in Oracle Coherence, a component within Oracle Fusion Middleware. The issue allows for easy exploitation by attackers over the network, potentially leading to a complete takeover of the Coherence system and severe impacts on confidentiality, integrity, and availability. Given its critical severity, confirming relevance and exposure within your environment is paramount.

  • Unauthenticated network access compromises Oracle Coherence.
  • Critical severity, potential for system takeover.
  • Verify if Oracle Coherence is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network requests to an exposed Oracle Coherence instance. Because the vulnerability is reachable via HTTP without any authentication, an attacker could compromise the entire Coherence system, leading to a complete takeover.

  • No authentication needed.
  • Network requests to Coherence.
  • Full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence, potentially leading to a complete takeover of the product. This could affect the confidentiality, integrity, and availability of data managed by Oracle Coherence when supported by the advisory.

  • Oracle Coherence product.
  • Network access via HTTP.
  • Takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, is likely to impact application owners and platform teams responsible for managing data grids and associated middleware. The first practical step is to identify all Oracle Coherence deployments, determine their network accessibility, and assess their criticality to business operations to prioritize remediation efforts.

  • Application or platform teams own remediation.
  • Verify network reachability and business impact.
  • Plan coordinated vendor and internal updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution used within Oracle Fusion Middleware. It serves as an in-memory data management layer that helps distributed applications store and share data across clusters, acting as a high-performance backend component for enterprise systems.

How does CVE-2026-60290 affect Oracle Coherence?

This vulnerability represents a significant flaw in the product's core component. It allows an unauthorized user to bypass security controls and gain full control over the system. Essentially, it permits an outsider to manipulate the software's operations and data by sending malicious instructions.

Do I need to be authenticated to trigger this vulnerability?

No. The flaw does not require any login or verified credentials to exploit. An attacker only needs network-level connectivity to the affected service via HTTP. Requests that do not use the specific HTTP path or protocol interactions required by the software's interface will not trigger the bug.

Is my Oracle Coherence instance at risk?

Halo Surface Signal notes that while this vulnerability is reachable via network requests, Oracle Coherence is typically deployed in internal backend tiers. Instances protected from the internet have a reduced risk profile compared to those directly exposed to public traffic.

How should I respond to this threat advisory?

Begin by auditing your environment to locate all Oracle Coherence installations. Assess how each instance is configured, specifically checking if they are reachable over a network. Prioritize reviewing systems with higher business criticality and coordinate with your platform teams to plan vendor-supplied updates.

References