Junglewise Threat Intelligence

CVE-2026-83236: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-83236 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search is a component that powers product search and navigation on e-commerce platforms. This vulnerability allows an attacker to trick users into performing unauthorized actions (such as modifying product data or accessing sensitive information) through a malicious link or webpage, without requiring the user to log in first. Successful exploitation can lead to theft of customer data or unauthorized modification of product and pricing information.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in the Oracle Commerce Experience Manager component of Oracle Commerce Guided Search version 11.4.0. The vulnerability is easily exploitable and requires no authentication, making it accessible to any network attacker. However, successful exploitation requires social engineering to trick a legitimate user into clicking a malicious link or visiting a crafted webpage (UI required). Once triggered by a user, an attacker can read sensitive data with high confidence and modify or delete some data with lower impact. The vulnerability has network-level reachability and affects the confidentiality and integrity of data accessible through the application.

Affected products

  • Oracle Commerce Guided Search 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats