CVE-2026-83411
nicheLow-Privilege HTTP Takeover Flaw in Oracle Coherence (Fusion Middleware Core)
CVE-2026-83411 is a high-severity vulnerability (CVSS 3.1: 8.8) in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. A remote attacker who already holds low-privileged credentials and has HTTP network access to the Coherence service can exploit the flaw easily and achieve a complete takeover of Oracle Coherence, with high impact on confidentiality, integrity, and availability. The affected supported versions are 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.1.0's predecessor 15.1.1.0.0, so organizations running those releases are exposed wherever the Coherence endpoints are reachable by low-trust users. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is currently no evidence of active exploitation. Patching should still be treated as a priority because exploitation requires only an authenticated, low-privileged account and yields full compromise.
What to do: Apply Oracle's Critical Patch Update fixes for Coherence on 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 as soon as they are available. Restrict HTTP access to Coherence cluster, proxy, and management endpoints to trusted networks and require strong authentication and TLS. Review local low-privileged account activity and Coherence logs for anomalous privilege escalation or unexpected administrative actions.
| Oracle Coherence (Oracle Fusion Middleware, component: Core) | 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.