Junglewise Threat Intelligence

CVE-2026-83259: Oracle Commerce Guided Search access control weakness in Forge

CVE-2026-83259 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Oracle Commerce Experience Manager, which power online shopping experiences, contain an access control vulnerability in their Forge component that allows low-privileged attackers to access sensitive customer and product data. An attacker can view critical business data or disrupt service availability, potentially exposing customer information and impacting e-commerce operations.

Technical details

The vulnerability is an access control weakness in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It requires low privilege access and network reachability via HTTP, with no user interaction needed. An unauthenticated or low-privileged attacker can exploit this to read unauthorized data or cause partial denial of service. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L) indicates the attack requires low privileges and network access but is otherwise straightforward to execute. Patch availability was not disclosed in the advisory reference materials.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed: Public disclosure via Oracle security alert and NVD

References

Related threats