External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60298

Oracle Coherence is a data grid solution typically deployed within internal application tiers, backend clusters, or middleware environments. While it uses TCP networking and can be exposed if misconfigured or improperly segmented, it is not designed as a public-facing edge service or internet gateway, making direct exposure to the public internet uncommon in standard deployments.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue could allow an attacker to gain complete control of the Coherence system. The potential impacts on confidentiality, integrity, and availability are severe.

  • Unauthenticated attackers can seize control of systems.
  • High impact if Oracle Coherence is part of your infrastructure.
  • Confirm relevance and exposure within your environment.

Attack Path

How an attacker could exploit the issue

An attacker can target Oracle Coherence by sending network requests over TCP. This vulnerability is accessible to attackers without any authentication, and a successful attack can lead to complete takeover of the affected Oracle Coherence system.

  • No prior authentication needed.
  • Network access via TCP.
  • Full system takeover possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access can compromise Oracle Coherence, potentially leading to a complete takeover of the system. This vulnerability impacts Confidentiality, Integrity, and Availability due to its network-accessible nature and lack of authentication requirements, when supported by the advisory.

  • Oracle Coherence system data.
  • Unauthenticated network access.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a typical deployment, Oracle Coherence is an internal middleware component, meaning application owners and platform teams are likely responsible for its management. The first practical step is to identify all Coherence instances, confirm their network exposure and criticality, and then assign ownership for remediation planning.

  • Application and platform teams own this.
  • Verify network reachability and asset criticality.
  • Plan remediation based on confirmed exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used to manage, store, and process data across clusters of servers. It acts as a middleware component within Oracle Fusion Middleware, helping applications scale by keeping frequently accessed data in memory rather than relying solely on a backend database. It is commonly found in enterprise environments to support high-performance, distributed applications.

What does CVE-2026-60298 mean for the system?

This vulnerability indicates a flaw in the core functionality of Oracle Coherence that lacks sufficient access controls. Because it does not verify the identity of the requester, an unauthorized party could send crafted commands to the system. This allows the attacker to execute unauthorized actions, effectively taking control of the Coherence instance and compromising the data it manages.

How can an attacker trigger this vulnerability?

An attacker triggers this issue by establishing a direct TCP network connection to an affected Oracle Coherence instance. No login credentials or prior authentication are required to initiate the attack. Crucially, the vulnerability cannot be triggered unless the attacker has network reachability to the specific port used by the Coherence service; it does not trigger through standard application-level user interactions.

Do I need to worry if my Coherence instance is internal?

According to Halo Surface Signal, Oracle Coherence is typically used in backend clusters and is not designed as a public-facing edge service. While you should prioritize instances that are accidentally exposed to the internet, you should still evaluate internal systems. Even if not public, the vulnerability is highly dangerous if an attacker gains access to your internal network.

How should I respond to this vulnerability?

Start by identifying all instances of Oracle Coherence running within your infrastructure to determine which versions are in use. Verify if any instances are reachable from untrusted network segments. Once you have an inventory, coordinate with your platform and application teams to assess the criticality of those assets and establish a timeline for applying the necessary security updates from Oracle.

References