External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60299

Oracle Coherence is a data grid and caching layer typically deployed within internal application tiers to support backend services. While it uses TCP for network communication, it is generally intended to be isolated from the public internet within a private data center or cloud VPC. It is not typically exposed directly to the public internet by design.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware that manages data caching and grids. This issue is easily exploitable by an unauthenticated attacker over a network, potentially leading to a complete takeover of the Coherence system and severe impacts on confidentiality, integrity, and availability. The main concern is confirming if this technology is in use and if it is exposed in a way that aligns with the vulnerability's external access vector.

  • Unauthenticated network access can seize Oracle Coherence systems.
  • Critical systems may be at risk if Coherence is exposed externally.
  • Confirm Oracle Coherence usage and external exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target Oracle Coherence by sending network requests over TCP. This can lead to a complete takeover of the Oracle Coherence system, impacting its confidentiality, integrity, and availability.

  • Network access required.
  • TCP network requests trigger.
  • System takeover risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to take over Oracle Coherence. This means an attacker could potentially gain full control over the Coherence system.

  • Oracle Coherence system data.
  • Network access via TCP.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence, an easily exploitable issue allowing unauthenticated network attackers to take over the system, likely falls under the responsibility of infrastructure or platform teams managing Oracle Fusion Middleware. The first practical step is to identify all deployments of Oracle Coherence, confirm their network exposure and business criticality, then assign ownership to the appropriate team for a risk-based remediation plan.

  • Infrastructure or platform teams own resolution.
  • Verify Coherence network exposure and criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution within Oracle Fusion Middleware. It provides distributed caching and data management, enabling applications to store and access data across clusters of servers for high-performance processing. Organizations use it to build scalable, fault-tolerant backend services that handle large volumes of data.

What does CVE-2026-60299 mean for Oracle Coherence?

This CVE identifies a critical vulnerability in the Coherence Core component. It allows an unauthenticated attacker to remotely compromise the system. In technical terms, it represents a severe weakness where the application fails to properly validate or handle network-based input, leading to a complete takeover of the affected system's operations.

How is this vulnerability triggered?

The flaw is triggered when an attacker sends specific, unauthorized requests over TCP to an affected Oracle Coherence instance. Because the system does not require prior authentication, the attacker can interact with the service directly. Notably, standard internal application traffic that does not attempt to exploit the underlying core management protocols will not trigger this condition.

Do I need to worry if my Coherence instance is internal?

While Halo Surface Signal classifies this as an external attack vector due to the TCP requirement, the risk depends on your network architecture. Oracle Coherence is typically designed for use within private data centers or VPCs. If your deployment is properly isolated from the public internet, it lacks the direct network path an external attacker requires to reach the component.

How should I respond to CVE-2026-60299?

Your first step is to locate all instances of Oracle Coherence across your infrastructure. Once identified, verify their network configuration to confirm whether they are accessible from untrusted networks. Work with your platform or infrastructure teams to prioritize those instances that are exposed, and coordinate with your organization's security patching process to apply the official updates provided by Oracle.

References