Executive brief
Oracle Commerce Guided Search and Experience Manager are e-commerce platform components that power product search and catalog management. A vulnerability in the Forge component allows a low-privileged attacker with local access to the server to gain full control over the system and potentially impact other connected services, affecting the confidentiality, integrity, and availability of the entire e-commerce platform.
Technical details
This is a privilege escalation vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) affecting version 11.4.0. The vulnerability has a CVSS 3.1 score of 7.8 with a local attack vector (AV:L), high complexity (AC:H), and requires low privileges (PR:L) to exploit. An authenticated attacker with local access to the infrastructure can achieve complete system compromise with impacts on confidentiality, integrity, and availability. The scope is changed, meaning the vulnerability may significantly impact additional products beyond the vulnerable component itself. No patch status or detailed mitigation information is currently available in the advisory materials provided.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed: CVE-2026-83249 published