CVE-2026-83411
Oracle · Oracle Coherence
A high-severity vulnerability in Oracle Coherence allows authenticated attackers with low privileges to gain full control of the application via network-based HTTP requests.
Executive summary
A critical security flaw in Oracle Coherence enables an authenticated attacker to achieve a complete system takeover of the affected middleware component.
Vulnerability
This vulnerability resides in the Core component of Oracle Coherence and is accessible via HTTP. It requires an attacker to possess low-level authentication to trigger the exploit, which leads to a full takeover of the Coherence instance.
Business impact
The potential for a full system takeover represents a severe risk to organizational data integrity and operational continuity. Given the CVSS 3.1 base score of 8.8, successful exploitation could lead to total unauthorized control over the middleware environment, resulting in data exfiltration or the manipulation of backend business processes.
Remediation
Immediate Action: Review the official Oracle security advisory for the latest Critical Patch Update and apply the corresponding patches to all instances of Oracle Coherence immediately.
Proactive Monitoring: Monitor network traffic and application logs for unusual HTTP requests targeting Coherence endpoints, particularly those originating from user accounts with limited permissions.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to filter malicious traffic and restrict access to the Coherence management interface to authorized subnets only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the high severity of this vulnerability and the potential for a complete system takeover, it is imperative that administrators prioritize the identification and patching of all affected Oracle Coherence versions. Organizations should treat this as a high-priority maintenance task to prevent potential unauthorized access.
More Oracle CVEs all →
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
- Oracle Advisory Vendor advisory