Junglewise Threat Intelligence

CVE-2026-83246: Oracle Commerce Guided Search and Experience Manager remote code execution

CVE-2026-83246 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager is an e-commerce search and merchandising platform used by online retailers. An unauthenticated attacker can exploit a vulnerability in the Forge component over the network to achieve complete takeover of the system, compromising customer data, product catalogs, and transaction processing.

Technical details

This is a difficult-to-exploit remote code execution vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker with network access via HTTP can exploit this flaw without user interaction. The vulnerability allows an attacker to compromise the affected system, resulting in complete takeover with impacts to confidentiality, integrity, and availability. The affected version is 11.4.0, and patches should be available from Oracle.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats