ZeroHour

CVE-2026-83410

moderate

Authenticated Remote Takeover Flaw in Oracle Coherence Core (Fusion Middleware)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83410 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. A low-privileged attacker with network access via multiple protocols can exploit the flaw easily to fully compromise the Oracle Coherence installation, with high impact on confidentiality, integrity and availability — effectively a complete takeover of the data-grid tier. Because it requires only low privileges (for example, an application-level or authenticated cluster user), the bar for exploitation is significantly lower than for unauthenticated flaws but still assumes some level of access. Organizations running the affected Coherence versions, whether standalone or embedded in WebLogic/Fusion Middleware deployments, are exposed, particularly where cluster or extend endpoints are reachable by untrusted networks. Exploitation status is benign at this time: the flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83410 to all supported Coherence releases (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0), prioritizing any instances reachable from less-trusted networks. Restrict network access to Coherence cluster, Coherence*Extend, and management ports so only trusted application hosts can connect, and enforce strong authentication/least-privilege for any low-privilege accounts that can reach those protocols. Audit logs for unexpected authenticated activity against Coherence endpoints to rule out silent exploitation.

Affected
Oracle Coherence (Oracle Fusion Middleware, component: Core)12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Estimated exposure
moderate≈1,000–10,000 internet-reachable Coherence endpoints; total enterprise deployments likely in the tens of thousands but mostly internal — Oracle Coherence is enterprise middleware typically deployed inside data centers as a caching/data-grid layer within WebLogic and Fusion Middleware environments, so internet-wide scans (e.g., Shodan/FOFA on known Coherence cluster and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.