Junglewise Threat Intelligence

CVE-2026-83249: Oracle Commerce Guided Search privilege escalation in Forge

CVE-2026-83249 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platform components that power product search and catalog management. A vulnerability in the Forge component allows a low-privileged attacker with local access to the server to gain full control over the system and potentially impact other connected services, affecting the confidentiality, integrity, and availability of the entire e-commerce platform.

Technical details

This is a privilege escalation vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) affecting version 11.4.0. The vulnerability has a CVSS 3.1 score of 7.8 with a local attack vector (AV:L), high complexity (AC:H), and requires low privileges (PR:L) to exploit. An authenticated attacker with local access to the infrastructure can achieve complete system compromise with impacts on confidentiality, integrity, and availability. The scope is changed, meaning the vulnerability may significantly impact additional products beyond the vulnerable component itself. No patch status or detailed mitigation information is currently available in the advisory materials provided.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed: CVE-2026-83249 published

References

Related threats