Executive brief
Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used to power product discovery and customer experiences. A flaw in the Forge component allows an attacker with physical access to the network segment containing the affected system to bypass authentication and gain unauthorized access to sensitive business data, modify records, or crash the service.
Technical details
This is a difficult-to-exploit vulnerability affecting the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager versions 11.4.0. The vulnerability requires the attacker to be physically present on the same network segment (adjacent network vector) with no authentication required. A successful attack can result in unauthorized read access to all sensitive data, partial write/delete access to data, and denial of service through system crashes. The exact root cause and patch availability are not detailed in the advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed: CVE-2026-83244 published