Junglewise Threat Intelligence

CVE-2026-83416: Oracle Coherence partial denial of service via HTTP

CVE-2026-83416 · Severity: medium · CVSS 4.3 · Published 2026-09-15

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence is a distributed data caching and processing platform used in enterprise applications to improve performance and availability. A vulnerability in the Core component allows an authenticated attacker to partially disrupt the service, reducing availability to legitimate users. This could impact business operations that depend on Coherence for real-time data processing and caching.

Technical details

This is a partial denial-of-service vulnerability in Oracle Coherence affecting the Core component. The vulnerability is easily exploitable and requires low-level privileges with network access via HTTP. No code execution or data confidentiality/integrity impacts are possible; only partial service availability is affected. The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Patches or mitigations should be available through Oracle's standard security update process.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats