Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data compromise via unauthorized access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Coherence 15.1.1.0.0 allows a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in unauthorized access to critical data or full access to all data accessible within Oracle Coherence, and may impact other Fusion Middleware components due to a scope change.

Affected Systems

The affected product is Oracle Coherence from Oracle Corporation, version 15.1.1.0.0. No other vendors or product versions are listed as vulnerable in the CNA data.

Risk and Exploitability

The CVSS v3.1 base score of 6.3 indicates a medium severity with a confidentiality impact and a scope change. The EPSS score is less than 1%, showing a low but nonzero exploitation probability in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based via HTTP, requiring only low privileges and no user interaction. Given the moderate severity score and low EPSS, the overall risk is moderate; however, the potential to compromise sensitive data warrants prompt remedial action.

Generated by OpenCVE AI on September 22, 2026 at 20:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a fixed release for Oracle Coherence 15.1.1.0.0 that addresses the access‑control flaw.
  • Restrict external HTTP access to Coherence nodes by configuring firewalls or network ACLs to allow only trusted internal traffic.
  • Monitor and audit HTTP traffic to Coherence endpoints for anomalous requests that could indicate attempted exploitation, and enforce strict role‑based access controls within the cluster.

Generated by OpenCVE AI on September 22, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Access Leads to Data Exposure in Oracle Coherence

Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Coherence via HTTP
Weaknesses CWE-286

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Coherence via HTTP
Weaknesses CWE-286

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Oracle Coherence
Weaknesses CWE-284

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Oracle Coherence
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:11:53.257Z

Reserved: 2026-08-31T15:40:57.354Z

Link: CVE-2026-83354

cve-icon Vulnrichment

Updated: 2026-09-22T14:11:50.617Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:48.910

Modified: 2026-09-22T15:17:17.517

Link: CVE-2026-83354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:30:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor