Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in the Oracle Coherence Core component leverages improper privilege management (CWE-269) to allow an attacker with low privileges and network access via HTTP to gain unauthorized control. The flaw permits unauthorized execution of privileged operations and ultimately full takeover of the Coherence cluster, resulting in total loss of confidentiality, integrity, and availability. By exploiting this weakness, a remote attacker can perform any actions that the privileged user can, up to full cluster compromise, without requiring additional credentials.

Affected Systems

Oracle Coherence, versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, are affected. These are provided as part of Oracle Fusion Middleware. No other products or releases are listed as impacted.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 marks this as high severity. Its EPSS score is below 1%, meaning the current exploitation probability is low, and it is not listed in the CISA KEV catalog. Nevertheless, the flaw is remotely exploitable over an open HTTP interface and requires only low privileges, so exposed systems remain at significant risk of immediate takeover.

Generated by OpenCVE AI on September 20, 2026 at 07:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Coherence 14.1.1.0.0, 14.1.2.0.0 or 15.1.1.0.0 as released by Oracle Fusion Middleware.
  • Restrict HTTP access to Coherence to trusted networks or block the exposed ports using firewall or network ACLs.
  • Enforce strict authentication and authorization controls for all Coherence management interfaces and disable any default or legacy unsecured ports.

Generated by OpenCVE AI on September 20, 2026 at 07:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Enables Coherence Takeover
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Enables Coherence Takeover
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:25.073Z

Reserved: 2026-08-31T15:40:57.357Z

Link: CVE-2026-83411

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:06.695Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:49.470

Modified: 2026-09-21T14:58:22.420

Link: CVE-2026-83411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management