External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60297

Oracle Coherence is typically used as a distributed cache or data grid within internal application tiers rather than as a public-facing service. While it is network-accessible and theoretically reachable if misconfigured in a DMZ, common deployments place this middleware deep within an internal network architecture, making direct public internet exposure uncommon.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware, that could allow an unauthenticated attacker to gain complete control of the system. This issue is rated as critical due to its potential for significant impact on confidentiality, integrity, and availability.

  • Unauthenticated attackers can take over Oracle Coherence.
  • Critical vulnerability impacts core business data and systems.
  • Confirm relevance and exposure within your Oracle Coherence deployments.

Attack Path

How an attacker could exploit the issue

An attacker could gain control of Oracle Coherence by sending specially crafted network requests. This vulnerability requires no authentication and can be exploited remotely, potentially allowing an attacker to fully compromise the system.

  • Attacker needs network access.
  • Attacker sends network requests.
  • Risk of complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of the service.

  • Oracle Coherence system.
  • Network access via TCP.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are most likely responsible for addressing this vulnerability in Oracle Coherence, a component typically found within internal application tiers. The initial step involves identifying all instances of the affected technology, assessing their reachability and business criticality, and then pinpointing the accountable owner to prioritize and plan remediation efforts based on risk.

  • Application and infrastructure teams own this.
  • Verify affected Oracle Coherence instances.
  • Plan remediation based on criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed cache and data grid software component within Oracle Fusion Middleware. It enables applications to store and manage data across multiple servers simultaneously, ensuring high availability and rapid access for performance-heavy enterprise tasks. It is frequently used as a foundational middleware layer to support complex, high-transaction application environments.

How does CVE-2026-60297 compromise the system?

This vulnerability allows an unauthenticated attacker to remotely take over the Oracle Coherence system. Because the software fails to properly handle certain network requests, an attacker can exploit this weakness to gain complete control over the service, severely impacting the confidentiality, integrity, and availability of the data it manages.

Do I need special access to trigger this bug?

An attacker only needs network access to the target system via TCP to initiate an attack. No login credentials or prior authentication are required. It is important to note that this does not imply the software is inherently public; the trigger simply requires that the attacker be able to send network traffic to the specific port where the Coherence service is listening.

Is my Oracle Coherence deployment at risk?

According to Halo Surface Signal, Oracle Coherence is typically used in internal application tiers rather than as a public-facing service. While the vulnerability is network-accessible, the risk depends heavily on your network architecture. If your instance is misconfigured in a DMZ or directly exposed to the internet, your risk is significantly higher than if it remains tucked deep within an internal network.

What steps should I take if I run Oracle Coherence?

Start by identifying all instances of Oracle Coherence across your environment to understand your footprint. Once mapped, confirm which instances are reachable over your network and assess their business criticality. Coordinate with the relevant infrastructure or application owners to prioritize these systems for necessary updates or mitigation strategies based on their specific exposure.

References