CVE-2026-83413
Analyzed Analyzed - Analysis Complete

Oracle Coherence Core Privilege Escalation

Vulnerability report for CVE-2026-83413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-22

Assigner: Oracle

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-22
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
oracle coherence 12.2.1.4.0
oracle coherence 14.1.1.0.0
oracle coherence 14.1.2.0.0
oracle coherence 15.1.1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Coherence, a middleware product. It allows a highly privileged attacker with local access to modify some data within Oracle Coherence, potentially leading to unauthorized changes.

Detection Guidance

This vulnerability requires high privileged attacker access with logon to the infrastructure. Detection involves monitoring for unauthorized data modifications in Oracle Coherence. Check application logs for suspicious activity and verify data integrity. No specific commands are provided in the context.

Impact Analysis

If you use Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0, an attacker with high privileges and local access could alter data, affecting integrity of stored information.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized data modifications, which may violate integrity requirements in GDPR or HIPAA if sensitive data is altered without authorization.

Mitigation Strategies

Apply the latest Oracle Coherence patches for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Restrict logon access to infrastructure where Oracle Coherence executes to only trusted users. Monitor logs for unauthorized data modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart