Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The core component of Oracle Coherence is vulnerable to a network‑level weakness that allows an attacker with low privileges and HTTP access to gain full control of the Coherence service. Successful exploitation can result in a compromise that affects confidentiality, integrity, and availability, effectively taking over the Coherence deployment.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and, based on the description, it is inferred that they may be deployed in a variety of environments, including public and private clouds.

Risk and Exploitability

The CVSS 3.1 vector indicates remote network access, high attack complexity and low privileges, yet the impact is complete control of the service. With an EPSS score of less than 1%, the current risk of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack path likely involves an unprotected HTTP management interface that the attacker can remotely access without authentication.

Generated by OpenCVE AI on September 20, 2026 at 07:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch that addresses the known issue for the affected Coherence versions.
  • Reconfigure the Coherence service so that the HTTP management interface is bound only to trusted networks or localhost, or otherwise disable it if not needed.
  • Enforce network segmentation or firewall rules to restrict HTTP traffic to Coherence nodes, ensuring that only authorized hosts can reach the vulnerable endpoints.

Generated by OpenCVE AI on September 20, 2026 at 07:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Vulnerability Enables Low-Privileged HTTP Attacker to Take Over Service

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Vulnerability Enables Low-Privileged HTTP Attacker to Take Over Service
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:24.921Z

Reserved: 2026-08-31T15:40:57.357Z

Link: CVE-2026-83415

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:02.478Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:49.903

Modified: 2026-09-21T18:06:21.757

Link: CVE-2026-83415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management