External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60308

Oracle Coherence is a data grid solution typically deployed within internal application tiers to support middleware services. While the vulnerability is reachable via HTTP, this product is generally intended for backend data caching and processing rather than being directly exposed to the public internet in standard deployment patterns.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Oracle Coherence, a component of Oracle Fusion Middleware. This issue, which can be exploited remotely and without authentication, could lead to a complete takeover of the Coherence environment, impacting confidentiality, integrity, and availability. The primary concern is to confirm if this technology is used within your organization and assess any potential exposure.

  • An attacker can fully control the system.
  • It impacts a core data management technology.
  • Confirm relevance and check for any exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach Oracle Coherence without any authentication by sending specially crafted requests over a network. This allows them to interact with the core component of the product, potentially leading to a complete takeover of the Coherence system.

  • Attacker can send network requests.
  • No authentication is required.
  • Complete system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Coherence, when deployed in supported configurations, could allow an unauthenticated attacker with network access to potentially take over the entire Oracle Coherence system. This could impact the confidentiality, integrity, and availability of the data managed by Coherence.

  • System data and service behavior.
  • Network access via HTTP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence product is a data grid solution often used within internal application tiers to support middleware services. Given its typical deployment as a backend component, the first practical step is to identify all instances of Oracle Coherence within your environment. Confirm which of these instances are reachable externally, assess their business criticality, and identify the accountable owners to prioritize remediation efforts based on risk.

  • Identify Oracle Coherence owners.
  • Verify external reachability and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that is part of the Oracle Fusion Middleware suite. It is primarily used by developers and enterprises to provide fast data caching, reliable storage, and distributed processing capabilities for high-performance applications. By managing data in memory across multiple servers, it helps middleware services scale and maintain consistent access to information across complex, distributed environments.

How does CVE-2026-60308 affect Oracle Coherence?

CVE-2026-60308 represents a critical security flaw in the core component of Oracle Coherence. It is categorized as a high-severity vulnerability that allows an attacker to interact with the system without needing any credentials. If triggered, this weakness could grant an unauthorized party complete control over the Coherence environment, directly compromising the confidentiality, integrity, and availability of the data and services it manages.

What is required for an attacker to trigger this vulnerability?

To exploit this issue, an attacker needs network access to the Oracle Coherence service and the ability to send specifically crafted HTTP requests. It is important to note that the vulnerability does not require any prior authentication or user interaction to occur. Conversely, the bug is not triggered by normal administrative operations or standard read/write requests that do not contain the malicious payload designed to interact with the vulnerable core component.

Is my Oracle Coherence instance at high risk?

According to Halo Surface Signal, risk depends heavily on how your system is positioned. While the vulnerability is reachable over a network, Oracle Coherence is typically deployed in internal application tiers to support backend middleware rather than being directly exposed to the public internet. Instances that are isolated from external traffic are generally at lower immediate risk than those unintentionally configured to be reachable from outside your network.

What should I do first to address this CVE?

Your first step is to perform an internal audit to locate every instance of Oracle Coherence running within your environment. Once identified, verify whether any of these instances are accessible from external networks. After mapping these installations, prioritize those that are internet-facing or hold business-critical data, and coordinate with the respective system owners to manage the risk and apply the necessary updates provided by the vendor.

References