ZeroHour

CVE-2026-83411

niche

Low-Privilege HTTP Takeover Flaw in Oracle Coherence (Fusion Middleware Core)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83411 is a high-severity vulnerability (CVSS 3.1: 8.8) in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. A remote attacker who already holds low-privileged credentials and has HTTP network access to the Coherence service can exploit the flaw easily and achieve a complete takeover of Oracle Coherence, with high impact on confidentiality, integrity, and availability. The affected supported versions are 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.1.0's predecessor 15.1.1.0.0, so organizations running those releases are exposed wherever the Coherence endpoints are reachable by low-trust users. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is currently no evidence of active exploitation. Patching should still be treated as a priority because exploitation requires only an authenticated, low-privileged account and yields full compromise.

What to do: Apply Oracle's Critical Patch Update fixes for Coherence on 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 as soon as they are available. Restrict HTTP access to Coherence cluster, proxy, and management endpoints to trusted networks and require strong authentication and TLS. Review local low-privileged account activity and Coherence logs for anomalous privilege escalation or unexpected administrative actions.

Affected
Oracle Coherence (Oracle Fusion Middleware, component: Core)14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Estimated exposure
nichelikely hundreds to low thousands of internet-reachable Coherence endpoints; total enterprise deployments unknown — Oracle Coherence is enterprise data-grid middleware typically deployed inside WebLogic/Fusion Middleware estates behind firewalls, with no public install counts and comparatively few exposed cluster/proxy ports visible in public internet…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.