External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60296

Oracle Coherence is a data grid solution typically deployed in back-end infrastructure for clustering and caching. While it uses TCP and is accessible via network, it is generally architected to reside within internal tiers rather than being directly exposed to the public internet. Internet exposure is possible in misconfigured or specific setups but is not the standard deployment pattern.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by an unauthenticated attacker over the network, potentially leading to a complete takeover of the Coherence system and impacting confidentiality, integrity, and availability.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • This system often manages critical data and operations.
  • Confirm relevance and any potential exposure of Coherence.

Attack Path

How an attacker could exploit the issue

An attacker with network access can compromise Oracle Coherence by exploiting an easily exploitable vulnerability. This vulnerability allows an unauthenticated user to gain full control of the Coherence system, potentially leading to data breaches, system manipulation, or complete service disruption.

  • Unauthenticated network access required.
  • TCP network connection triggers vulnerability.
  • Complete system takeover possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a full takeover of the system. This could affect the confidentiality, integrity, and availability of the Coherence service and its data.

  • Oracle Coherence system.
  • Network access via TCP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are likely responsible for Oracle Coherence, a component of Oracle Fusion Middleware. The first practical step is to locate all Coherence instances, determine their business criticality and network exposure, identify the accountable owners, and then prioritize remediation efforts based on risk.

  • Identify affected Oracle Coherence instances.
  • Verify network exposure and business criticality.
  • Plan coordinated remediation with Oracle.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that serves as a caching and clustering layer within Oracle Fusion Middleware. Developers use it to manage, store, and process large volumes of data across distributed applications, ensuring high performance and scalability for backend infrastructure.

What does CVE-2026-60296 mean for my system?

This CVE represents a critical security flaw in the core component of Oracle Coherence. It allows an unauthenticated attacker to remotely compromise the software. This weakness means an unauthorized person can gain full control over the data grid, which could lead to the exposure or manipulation of the critical data managed by the system.

How is CVE-2026-60296 triggered?

An attacker triggers this vulnerability by establishing a network connection to the Oracle Coherence service using the TCP protocol. No authentication or user interaction is required to initiate the attack. Notably, the vulnerability requires network reachability to the Coherence component itself; internal processes that do not accept external or unauthorized TCP traffic do not trigger the flaw.

Do I need to worry if my Coherence instances are internal?

Yes, but your risk profile may differ. Halo Surface Signal notes that Oracle Coherence is typically deployed in internal infrastructure rather than directly on the public internet. However, because the vulnerability allows for a complete system takeover via TCP, any internal actor or compromised machine with network path access to these instances could still exploit the system.

How should I respond to this vulnerability?

Begin by inventorying your environment to locate all running instances of Oracle Coherence across your infrastructure. Once identified, evaluate the network accessibility and business criticality of each instance. Identify the teams responsible for these applications and coordinate with them to prioritize the application of official Oracle security updates.

References