Junglewise Threat Intelligence

CVE-2026-83354: Oracle Coherence unauthorized data access vulnerability

CVE-2026-83354 · Severity: medium · CVSS 6.3 · Published 2026-09-15

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence is an in-memory data grid product used by enterprises to cache and manage critical application data. A vulnerability in the Core component allows a low-privileged network attacker to gain unauthorized access to sensitive data stored in Coherence, potentially exposing customer information and confidential business records. The vulnerability can also impact other Oracle products that depend on Coherence.

Technical details

This is a difficult-to-exploit confidentiality vulnerability in Oracle Coherence Core (version 15.1.1.0.0) that requires low privileges and network access via HTTP. The attack has a high complexity factor (AC:H) but no user interaction requirement. Successful exploitation grants an attacker unauthorized access to critical data or complete read access to all data accessible through Oracle Coherence. The vulnerability has scope change implications, meaning the impact extends beyond the Coherence product itself to dependent systems. Patches are expected from Oracle's regular security update channels.

Affected products

  • Oracle Coherence 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats