External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60302

Oracle Coherence is a data grid and caching layer typically deployed in back-end environments. While it requires network access and the vulnerability is reachable over TCP, it is generally designed for internal application tier communication rather than being exposed directly to the public internet in standard deployments.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware, that could allow an unauthenticated attacker to gain complete control of the system. This issue, rated with a CVSS score of 9.8, impacts confidentiality, integrity, and availability and is exploitable over a network connection.

  • Unauthorized access can lead to full system takeover.
  • Remember this for potential impacts on Oracle Coherence.
  • Confirm relevance and exposure in your Oracle Coherence environment.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending malicious network traffic to an exposed Oracle Coherence component. Since no authentication is required and the attack can be launched over a network, an unauthenticated attacker could directly interact with the vulnerable Core component. Successful exploitation could grant the attacker complete control over the Oracle Coherence system, impacting its confidentiality, integrity, and availability.

  • Unauthenticated network access required.
  • Core component is directly targeted.
  • Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of the Coherence service.

  • Oracle Coherence system data.
  • Network access via TCP.
  • Takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this is a vulnerability in Oracle Coherence, typically a backend component, the primary responsibility likely falls on the platform or infrastructure teams managing the middleware, alongside application owners who rely on Coherence for data management. The immediate practical step is to identify all Oracle Coherence instances, assess their network exposure and criticality, confirm ownership with the respective application or platform teams, and then collaboratively plan a risk-based remediation strategy.

  • Platform and application owners should prioritize this.
  • Verify Coherence instance network exposure and criticality.
  • Plan coordinated remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that provides distributed caching and data management. It acts as a middle-tier layer in enterprise software architectures, helping applications handle large volumes of data by storing it across multiple servers for fast access, which is why it is commonly used in back-end environments to support high-performance computing.

What does CVE-2026-60302 mean for system security?

This vulnerability indicates a flaw in the core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely. Because it affects the core, a successful attack grants the intruder complete control over the system, meaning they can read, modify, or delete the data stored in the grid and disrupt the service entirely.

How is this Oracle Coherence vulnerability triggered?

An attacker triggers this flaw by sending specially crafted network traffic to an Oracle Coherence instance over TCP. Because the software does not require authentication to process these requests, the attacker can interact with the vulnerable core directly. The vulnerability is not triggered by user-level actions within the application but rather by raw network interaction with the infrastructure layer.

Why should I care about CVE-2026-60302 in my network?

While Oracle Coherence is typically used for internal application tier communication, it remains a critical concern if those segments are reachable. According to Halo Surface Signal, although it is not usually intended for public internet exposure, any instance accessible via a network path is potentially at risk if an attacker can reach the TCP port used by the software.

What should I do if I run Oracle Coherence?

Begin by identifying all running instances of Oracle Coherence across your infrastructure. Once you have a complete inventory, determine which instances are accessible over your internal network. Coordinate with the platform and application teams who own these systems to assess their criticality and prioritize them for the necessary vendor-provided updates to mitigate the risk of unauthorized takeover.

References