CVE-2026-83412
moderateLow-Privilege Data Manipulation Flaw in Oracle Coherence (Fusion Middleware)
CVE-2026-83412 is an easily exploitable vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. A remote attacker with only low-privileged (authenticated) access who can reach the Coherence service over TCP can exploit the flaw. A successful attack allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to some or all data accessible through Oracle Coherence, with high impact to both confidentiality and integrity (CVSS 3.1 base score 8.1; availability is not affected). Organizations running Coherence clusters or Fusion Middleware deployments that embed Coherence on the affected versions are at risk, particularly where cluster endpoints are reachable beyond trusted internal networks. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation in the wild is not currently evidenced.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83412 to all affected Coherence installations (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) as soon as your patch cycle allows. Restrict TCP access to Coherence cluster and proxy ports so only trusted application servers can reach them, and enforce strong authentication to prevent low-privileged accounts from accessing cluster services. Review Coherence and surrounding Fusion Middleware logs for unexpected data reads, modifications, or deletions by low-privilege accounts.
| Oracle Coherence (Oracle Fusion Middleware, component: Core) | 12.2.1.4.0 |
| Oracle Coherence (Oracle Fusion Middleware, component: Core) | 14.1.1.0.0 |
| Oracle Coherence (Oracle Fusion Middleware, component: Core) | 14.1.2.0.0 |
| Oracle Coherence (Oracle Fusion Middleware, component: Core) | 15.1.1.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.