Junglewise Threat Intelligence

CVE-2026-83411: Oracle Coherence privilege escalation in Core

CVE-2026-83411 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence is an in-memory data grid used by enterprises to cache and distribute data across applications. A vulnerability in its Core component allows a low-privileged network user to gain complete control over the Coherence system, potentially compromising all cached data, services, and operations that depend on it. An attacker could read sensitive information, modify data, or disrupt service availability.

Technical details

This is a network-accessible vulnerability in Oracle Coherence Core that can be exploited by an attacker with low privileges via HTTP requests. The vulnerability has low attack complexity and requires no user interaction, making it easily exploitable. Successful exploitation results in complete compromise of the Coherence system, affecting confidentiality, integrity, and availability. The vulnerability affects versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0; patch or upgrade availability from Oracle should be verified through official security advisories.

Affected products

  • Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats