Junglewise Threat Intelligence

CVE-2026-83245: Oracle Commerce Guided Search remote code execution

CVE-2026-83245 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platforms used to deliver search and shopping experiences to customers. An unauthenticated remote vulnerability allows attackers to gain complete control over the system via the HTTP interface, potentially enabling theft of customer data, manipulation of product catalogs, or complete service disruption.

Technical details

The vulnerability is a difficult-to-exploit flaw in the Forge component of Oracle Commerce Guided Search / Experience Manager that permits unauthenticated, network-accessible remote code execution. An attacker requires no authentication credentials or user interaction to exploit this issue over HTTP. Successful exploitation results in complete system compromise, allowing an attacker to achieve confidentiality, integrity, and availability impacts. The vulnerability affects version 11.4.0; patch status from Oracle is currently unavailable in public sources.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats