ZeroHour

CVE-2026-83415

moderate

Low-Privilege Takeover Flaw in Oracle Coherence (Fusion Middleware Core)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

Oracle Coherence, the in-memory data grid component of Oracle Fusion Middleware (Core component), contains a vulnerability in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 that allows a low-privileged attacker with network access via HTTP to compromise the product. The flaw is rated difficult to exploit (CVSS 3.1 base score 7.5, AV:N/AC:H/PR:L), meaning the attacker must already hold some low-level credentials or session and overcome significant attack complexity. Successful attacks can result in a complete takeover of Oracle Coherence, with high impact on confidentiality, integrity and availability. Organizations running the affected Coherence releases, typically as part of WebLogic or broader Fusion Middleware deployments, are at risk. There is no known public proof of concept, no evidence of in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply Oracle's latest Critical Patch Update to all affected Coherence versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Restrict network and HTTP access to Coherence management and Extend endpoints to trusted sources, and review which low-privileged accounts can reach those services. Monitor Coherence logs for anomalous authenticated activity that could indicate exploitation attempts.

Affected
Oracle Coherence (Oracle Fusion Middleware, component: Core)12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Estimated exposure
moderatelikely low-thousands of internet-exposed Coherence endpoints, plus a larger unknown population of internal enterprise deployments — Oracle Coherence is enterprise middleware deployed mainly inside corporate data centers (often embedded in WebLogic), and public internet scan services typically show only on the order of a few thousand exposed Coherence ports, with most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.