Junglewise Threat Intelligence

CVE-2026-83257: Oracle Commerce Guided Search privilege escalation in Forge

CVE-2026-83257 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used to deliver search and merchandising features to online shoppers. A privilege escalation vulnerability allows a low-privileged attacker with network access to take complete control of these systems, potentially exposing customer data and disrupting shopping operations.

Technical details

This is a privilege escalation vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager versions 11.4.0. The vulnerability is difficult to exploit and requires low privileges and network access via HTTP. An attacker can exploit this flaw to achieve full system compromise, resulting in unauthorized access to confidentiality, integrity, and availability of the affected systems. Patch availability has not been confirmed from the provided advisory content.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats