Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution and System Takeover
Action: Immediate Patch
AI Analysis

Impact

The defect in Oracle Coherence allows an attacker with low privileges and network access to several protocols to take control of the Coherence instance. The vulnerability enables remote code execution, granting the threat actor full control over the target system, with the ability to read, modify, or delete data and to disrupt services. The weakness is consistent with an improper privilege management flaw.

Affected Systems

Oracle Corporation’s Oracle Coherence product is affected. The specific versions that are vulnerable include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are part of Oracle Fusion Middleware and rely on the Core component for distributed caching and data management.

Risk and Exploitability

The CVSS base score of 8.8 places this vulnerability in the high severity range. The EPSS score of less than 1% indicates that, at the time of analysis, the probability of exploitation in the wild is low, and the vulnerability is not catalogued in CISA’s KEV list. Nonetheless, the attack vector is inferred to be remote, requiring network connectivity to Coherence services and potentially low‑privilege credentials, but no user interaction or elevated privileges. Successful exploitation can result in complete takeover of the affected system, with full confidentiality, integrity, and availability compromise.

Generated by OpenCVE AI on September 20, 2026 at 07:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence release that contains the fix for CVE‑2026‑83410.
  • Restrict network access to Coherence instances, disabling unused protocols and enforcing strong authentication controls for all remote connections.
  • Continuously monitor network traffic and system logs for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 07:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Privilege Management in Oracle Coherence

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Coherence via Low‑Privilege Network Access Leads to Takeover
Weaknesses CWE-94

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Coherence via Low‑Privilege Network Access Leads to Takeover
Weaknesses CWE-94

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:25.238Z

Reserved: 2026-08-31T15:40:57.357Z

Link: CVE-2026-83410

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:10.819Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:49.350

Modified: 2026-09-21T18:06:30.143

Link: CVE-2026-83410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management