Junglewise Threat Intelligence

CVE-2026-83237: Oracle Commerce Guided Search authentication bypass in Forge

CVE-2026-83237 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platform components that power product search and storefront experiences for online retailers. A low-privileged attacker with network access can exploit this vulnerability to access sensitive customer or business data and temporarily disrupt service availability. The flaw requires only HTTP network access and affects a widely-used e-commerce platform, posing a risk to confidential data and operational continuity.

Technical details

This is an authorization or access control vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0). The vulnerability is easily exploitable by a low-privileged, network-accessible attacker via HTTP without requiring user interaction. Successful exploitation allows unauthorized read access to critical data and restricted functionality, as well as the ability to cause partial denial of service. The attack vector is network-based with low complexity and requires only low privilege credentials.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats