Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-09-15
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability resides in the core component of Oracle Coherence version 15.1.1.0.0 and allows an attacker who has logged on to the infrastructure where Coherence runs to read a subset of data exposed by the application. Because the technical flaw only permits limited confidential information to be accessed, the confidentiality impact is classified as low, yet the compromise could reveal sensitive or business logic data that may be valuable to an adversary. This vulnerability, identified as CWE-200, is a confidentiality exposure.

Affected Systems

Oracle Coherence 15.1.1.0.0, part of Oracle Fusion Middleware. The affected component is the Core module of the product.

Risk and Exploitability

The CVSS score of 2.5 reflects a low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is exploitable only from a logged‑on local session (Attack Vector: Local, Privileges: Low) and requires the attacker to have some level of access to the environment where Coherence runs. The vulnerability does not allow code execution or interruption of service; it is limited to unauthorized read of a limited data set. The product is not listed in the CISA KEV catalog, which further suggests that the publicly known exploitation of this weakness is unlikely at present.

Generated by OpenCVE AI on September 22, 2026 at 17:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the vulnerability in Coherence 15.1.1.0.0.
  • Restrict local access to the Coherence environment to users with strictly necessary privileges and enforce network segmentation to isolate the cache nodes from untrusted hosts.
  • Configure audit logging to detect and alert on anomalous read operations against Coherence data.
  • If an immediate patch is unavailable, limit or disable any exposed administrative or management interfaces that allow data queries from untrusted sources.

Generated by OpenCVE AI on September 22, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Local Logon Vulnerability Enabling Unauthorized Data Retrieval in Oracle Coherence

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Local Logon Vulnerability Enabling Unauthorized Data Retrieval in Oracle Coherence

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged Data Disclosure in Oracle Coherence 15.1.1.0.0
Weaknesses CWE-200

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged Data Disclosure in Oracle Coherence 15.1.1.0.0
Weaknesses CWE-200

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:31:08.070Z

Reserved: 2026-08-31T15:40:57.357Z

Link: CVE-2026-83414

cve-icon Vulnrichment

Updated: 2026-09-22T14:30:56.069Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:49.793

Modified: 2026-09-22T19:06:50.370

Link: CVE-2026-83414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T17:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor