Junglewise Threat Intelligence

CVE-2026-83412: Oracle Coherence unauthorized data access vulnerability

CVE-2026-83412 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence is an in-memory data grid product used to cache and manage critical application data across distributed systems. A low-privileged network attacker can exploit this vulnerability to read, modify, or delete sensitive business data stored in Coherence without proper authorization, potentially affecting all cached data in the system.

Technical details

This vulnerability in Oracle Coherence's Core component allows an authenticated attacker with low privileges to gain unauthorized access to data via a network-accessible TCP service. The attack requires no user interaction and succeeds due to an easily exploitable flaw that bypasses Coherence's access controls. Successful exploitation enables unauthorized creation, deletion, and modification of critical cached data as well as complete read access to all data stored in the Coherence instance. The vulnerability affects Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0; patched versions and remediation steps should be obtained from Oracle's security advisories.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats