Junglewise Threat Intelligence

CVE-2026-83251: Oracle Commerce Guided Search denial of service and information disclosure

CVE-2026-83251 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search is a search and merchandising component used in enterprise e-commerce platforms. An unauthenticated attacker can exploit a difficult-to-exploit vulnerability in version 11.4.0 to crash the service or read sensitive data, impacting both availability and data confidentiality for online stores relying on this component.

Technical details

This is a difficult-to-exploit vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) that is reachable over the network via TLS without authentication. An unauthenticated attacker with network access can trigger a denial of service (hang or crash) or gain unauthorized read access to a subset of accessible data. The vulnerability requires specific exploitation conditions, hence the "High Complexity" CVSS rating. Patching status and detailed root cause analysis are not available from the provided references.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats