Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-09-15
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Integrity Modification
Action: Assess Impact
AI Analysis

Impact

A local privilege vulnerability in Oracle Coherence allows an attacker who already has high privileged access to the underlying infrastructure to alter data stored within the Coherence cluster. The flaw does not enable code execution or affect confidentiality; its sole impact is to permit unauthorized updates, insertions, or deletions of data accessible through Coherence.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected.

Risk and Exploitability

The CVSS score of 1.9 reflects a low severity with only integrity impact. The EPSS score of less than 1% indicates a very low likelihood of exploitation observed in the wild. It is not listed in the CISA KEV catalog, and no publicly available exploit was reported. The vulnerability can only be exploited by a user who has already logged on with sufficient privileges to the machine running Coherence, so it is a local attack vector requiring local access and administrative rights.

Generated by OpenCVE AI on September 22, 2026 at 18:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch or upgrade to a non‑affected Oracle Coherence release.
  • Restrict local privileges on all servers hosting Coherence, limiting administrative login to trusted accounts and enforcing least privilege for any user with access to the Coherence environment.
  • Enable comprehensive audit logging for all data modification operations performed by Coherence and review logs regularly to detect any unauthorized insert, update, or delete actions.

Generated by OpenCVE AI on September 22, 2026 at 18:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Data Modification in Oracle Coherence

Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Data Modification in Oracle Coherence
Weaknesses CWE-285

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Data Modification in Oracle Coherence
Weaknesses CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Impact Integrity Vulnerability in Oracle Coherence Allowing Unauthorized Data Modification
Weaknesses CWE-284

Wed, 16 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low‑Impact Integrity Vulnerability in Oracle Coherence Allowing Unauthorized Data Modification
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:11:22.417Z

Reserved: 2026-08-31T15:40:57.357Z

Link: CVE-2026-83413

cve-icon Vulnrichment

Updated: 2026-09-22T14:11:17.028Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:49.690

Modified: 2026-09-22T19:06:57.103

Link: CVE-2026-83413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T18:45:18Z

Weaknesses