Junglewise Threat Intelligence

CVE-2026-83242: Oracle Commerce Guided Search data access vulnerability

CVE-2026-83242 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search / Experience Manager is a product used by e-commerce businesses to deliver search and product discovery features to customers. An unauthenticated attacker can exploit this vulnerability over the network to read, modify, or delete sensitive data, or disrupt service availability. The flaw requires no special credentials or user interaction to exploit.

Technical details

This is an unauthenticated data access and partial denial-of-service vulnerability in the Experience Manager component of Oracle Commerce Guided Search. The vulnerability is easily exploitable via HTTP and allows an attacker with network access to perform unauthorized read, insert, update, and delete operations on accessible data within the product, as well as cause partial service disruption. Attack requires no authentication or preconditions beyond network reachability. Oracle has published a security fix, though access to the Oracle security bulletin was unavailable at time of analysis.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats