Executive brief
Oracle Coherence is a distributed in-memory data grid platform used by enterprises to cache and manage application data. A network-accessible vulnerability in the Core component allows low-privileged attackers to gain complete control over Coherence systems through HTTP requests, potentially exposing sensitive cached data and disrupting business operations.
Technical details
A difficult-to-exploit privilege escalation vulnerability exists in Oracle Coherence Core component, accessible via HTTP to low-privileged authenticated users. The attack requires network access and authentication but has high complexity mitigations. Successful exploitation results in complete takeover of the Coherence instance, compromising confidentiality, integrity, and availability of cached data. This vulnerability affects Coherence versions 12.2.1.4.0 through 15.1.1.0.0. Patch availability has not been confirmed in available advisory references.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-09-15: disclosed: CVE-2026-83415 published in Oracle security advisory