{"id":"CVE-2026-83414","title":"Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core)","summary":"Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infr…","severity":"low","cvss":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"oracle","product":"coherence","affected":["coherence = 15.1.1.0.0"],"published":"2026-09-15","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:06:50.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-83414","references":[{"url":"https://www.oracle.com/security-alerts/cspusep2026.html","label":"secalert_us@oracle.com"}],"tags":["nvd","cve.org"],"epss":0.00128,"epssPercentile":0.02774,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-22T14:29:58.558807Z"},"ingestedAt":"2026-09-15T20:44:02.537Z","slug":"CVE-2026-83414","body":"## Overview\n\nVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).\n\n## Affected\n\n- `coherence = 15.1.1.0.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}