Junglewise Threat Intelligence

CVE-2026-83233: Oracle Commerce Experience Manager unauthorized data access

CVE-2026-83233 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager is a component used to manage guided search and customer experience features in enterprise e-commerce systems. A low-privilege attacker with network access can exploit this vulnerability to gain unauthorized access to sensitive customer and business data stored in the system, potentially exposing transaction history, customer profiles, and other confidential information.

Technical details

The vulnerability exists in Oracle Commerce Experience Manager (component of Oracle Commerce Guided Search / Experience Manager product) version 11.4.0. It is exploitable remotely over HTTP by an attacker with low-privilege credentials and does not require user interaction. The flaw enables unauthorized access to critical data accessible by the Experience Manager system, with scope change indicating potential impact to downstream systems and products that depend on this component. No information disclosure or availability impact occurs; the attack is read-only data exfiltration. The vulnerability has not been observed in active exploitation in the wild.

Affected products

  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats