Junglewise Threat Intelligence

CVE-2026-83247: Oracle Commerce Guided Search remote code execution in Forge

CVE-2026-83247 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components that handle product search and shopping experiences in e-commerce platforms. A vulnerability in the Forge component allows an attacker with local access to the infrastructure to execute arbitrary code and completely compromise the system, affecting the confidentiality, integrity, and availability of the e-commerce platform and customer data.

Technical details

This is a local privilege escalation or code execution vulnerability in the Forge component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. The vulnerability is easily exploitable from the local system (AV:L) with no privileges required (PR:N), but requires user interaction (UI:R) for successful exploitation. An unauthenticated attacker with logon access to the infrastructure can exploit this to achieve complete system compromise with high impact on confidentiality, integrity, and availability. No patch information is currently available from the advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats