Junglewise Threat Intelligence

CVE-2026-83413: Oracle Coherence integrity bypass in Core

CVE-2026-83413 · Severity: low · CVSS 1.9 · Published 2026-09-15

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence is an in-memory data grid used to cache and manage application data across distributed systems. A vulnerability in the Core component allows a privileged attacker with local access to perform unauthorized modifications (insert, update, delete) to data stored in Coherence, potentially compromising data integrity and application consistency.

Technical details

The vulnerability is an integrity bypass in the Core component of Oracle Coherence that requires high privileges and local logon access to the infrastructure where Coherence executes. The attack has high complexity and does not involve network access or user interaction. A successful exploit allows an attacker to perform unauthorized data manipulation operations (update, insert, delete) on Coherence-managed data. No integrity (C), availability (A), or confidentiality (I) impacts beyond integrity modification are present. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0; patch availability is not confirmed in available sources.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats