Junglewise Threat Intelligence

CVE-2026-83250: Oracle Commerce Guided Search remote access vulnerability in Forge

CVE-2026-83250 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components that power product discovery and search on e-commerce platforms. An unauthenticated attacker on the network can exploit this vulnerability via HTTP to access sensitive customer and product data without authorization, and cause temporary service disruptions to the shopping experience.

Technical details

This is a high-complexity, difficult-to-exploit vulnerability in the Forge component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. The vulnerability allows unauthenticated, network-accessible attackers to bypass authentication and gain unauthorized read access to critical data. The attack vector is HTTP and requires no user interaction, but has a high complexity barrier (AC:H). Successful exploitation results in confidentiality loss (access to protected data) and partial availability impact (partial DoS). A patch or mitigation is presumed available from Oracle given the published advisory date.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats