Junglewise Threat Intelligence

CVE-2026-83238: Oracle Commerce Guided Search privilege escalation in Forge

CVE-2026-83238 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used to help customers discover and purchase products in online stores. A low-privileged user with network access can exploit this vulnerability to view sensitive business data or temporarily disrupt service availability. This could lead to exposure of customer information or business disruption.

Technical details

This is a privilege escalation vulnerability in the Forge component of Oracle Commerce Guided Search / Experience Manager. The vulnerability is easily exploitable and requires only low-privileged user account access and network connectivity via HTTP; no additional user interaction is needed. A successful attack allows an attacker to access restricted data and cause partial denial of service. The affected version is 11.4.0. Oracle has assigned CVSS 3.1 score of 7.1, indicating high severity impacts to confidentiality and availability.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats