Junglewise Threat Intelligence

CVE-2026-83414: Oracle Coherence information disclosure in Core component

CVE-2026-83414 · Severity: low · CVSS 2.5 · Published 2026-09-15

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence is a distributed caching and data grid product used to accelerate application performance. A vulnerability in its core component allows a local user with low-level access to read sensitive data that they shouldn't be able to access, potentially exposing cached information used by enterprise applications.

Technical details

The vulnerability is an information disclosure flaw in the Oracle Coherence Core component affecting version 15.1.1.0.0. It requires local access (adjacent/local attack vector) and low privileges with valid logon credentials, plus non-standard conditions (high complexity), making it difficult to exploit in practice. Successful exploitation enables unauthorized read access to a subset of Oracle Coherence accessible data. The CVSS 3.1 score is 2.5 (low severity) reflecting confidentiality impact only, with no integrity or availability effects. Patch status and mitigation guidance are available through Oracle's standard security advisory channels.

Affected products

  • Oracle Coherence 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats