Junglewise Threat Intelligence

CVE-2026-83243: Oracle Commerce Experience Manager unauthorized data access

CVE-2026-83243 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager is a component used to manage and deliver personalized shopping experiences in e-commerce platforms. A low-privilege attacker with network access can exploit this vulnerability to gain unauthorized access to sensitive customer and business data stored in the system, potentially exposing payment information, personal details, and transaction history.

Technical details

This is an unauthorized access vulnerability in Oracle Commerce Experience Manager (part of Oracle Commerce Guided Search / Experience Manager product). The vulnerability is easily exploitable and requires low privilege credentials and network access via HTTP (no special client interaction needed). An authenticated attacker can achieve high-impact confidentiality compromise, with the scope extended to affect additional connected products. The affected version is 11.4.0; patch availability has not been confirmed in the advisory text.

Affected products

  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats