External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60300

Oracle Coherence is typically used as an in-memory data grid for internal application clustering and caching within an enterprise backend architecture. While it uses TCP for network communication, it is generally deployed within protected internal network segments rather than being exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue could allow an unauthorized attacker to gain complete control of the Coherence system, potentially impacting confidentiality, integrity, and availability. The primary concern is to confirm if this technology is used within our environment, as it typically operates within internal networks.

  • Unauthenticated attackers can take over Oracle Coherence.
  • Confirm if our Oracle Coherence is exposed externally.
  • Understand potential impact and our exposure level.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network requests to an exposed Oracle Coherence instance. Because no authentication is required and the vulnerability is easily exploitable over TCP, an attacker could gain complete control of the affected Coherence component, potentially leading to a full system takeover.

  • Attacker needs network access.
  • Unauthenticated network requests trigger it.
  • Complete takeover of Coherence.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a full takeover of the system. This vulnerability impacts the confidentiality, integrity, and availability of the Oracle Coherence service when supported versions are used.

  • Oracle Coherence service data and control.
  • Unauthenticated network access over TCP.
  • Complete takeover of the Coherence system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence component of Oracle Fusion Middleware is affected by this vulnerability. Ownership will likely fall to the platform or application teams responsible for managing Coherence deployments. The first practical step is to identify all Coherence instances, determine their network accessibility and business criticality, and then engage the accountable owners to prioritize remediation.

  • Platform or application teams own this.
  • Verify network reachability and business impact.
  • Plan remediation during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a specialized software component within Oracle Fusion Middleware. It functions as an in-memory data grid, which developers use to manage cached data and cluster applications for better performance. It helps high-traffic systems handle large volumes of information rapidly by keeping that data directly in the application's memory rather than constantly querying a traditional database.

How does CVE-2026-60300 impact the system?

This vulnerability acts as a flaw that allows an attacker to bypass security controls entirely. Because the software fails to verify the identity of someone sending requests, an unauthorized party can interact with the service as if they were a legitimate user. This results in a complete takeover, meaning the attacker gains full control over the service's functions, including the data it manages and its operational commands.

Do I need special access to trigger CVE-2026-60300?

The vulnerability requires network access to the target instance via TCP. It does not require any prior authentication, password, or login credentials to initiate the attack. However, simply having the software installed is not enough; the attacker must be able to reach the specific port used by the Oracle Coherence service over the network to send the malicious requests.

Is my Oracle Coherence instance at high risk?

According to Halo Surface Signal, risk depends heavily on network placement. Oracle Coherence is typically designed for internal backend architectures rather than public-facing services. While the vulnerability is technically critical, it is unlikely to be exposed to the public internet in standard configurations. Instances restricted to internal, protected network segments are less accessible to external attackers than those exposed publicly.

What are the first steps to address this CVE?

Begin by inventorying your environment to locate all running instances of the affected Oracle Coherence versions. Once identified, verify their network accessibility to determine if they are reachable from untrusted networks. Coordinate with the application or platform teams responsible for these systems to assess their business criticality and prepare for necessary security updates or configuration changes during your next maintenance window.

References