Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Data Access and Modification
Action: Immediate Patch
AI Analysis

Impact

Oracle Commerce Guided Search and Oracle Commerce Experience Manager allow an unauthenticated attacker, via HTTP, to read sensitive information and to perform update, insert or delete operations on selective data. The flaw results in a loss of confidentiality and a breach of data integrity, as the attacker can tamper with or remove critical Commerce data. This weakness is a classic example of improper access control combined with insufficient authentication.

Affected Systems

Affected vendor is Oracle Corporation. The product at risk is Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other versions or components are currently listed as vulnerable.

Risk and Exploitability

The CVSS base score of 8.2 marks this vulnerability as high severity, and the EPSS score indicates a very low exploitation probability (<1%). It is not currently listed in the CISA KEV catalog. The likely attack vector is an unauthenticated, network‑level HTTP request to the exposed service, requiring no prior credentials. Because the vulnerability is straightforward to exploit from any network with HTTP access, the overall risk remains significant, especially if the service is exposed to external networks.

Generated by OpenCVE AI on September 20, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle's published patch for Oracle Commerce Experience Manager 11.4.0 or upgrade to a version that is not affected
  • Configure network controls such as firewalls or VPNs to limit HTTP access to trusted hosts
  • If the exposed Commerce API is not required, disable or block it to reduce the attack surface

Generated by OpenCVE AI on September 20, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Data Access and Modification in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284
CWE-306

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Manipulation in Oracle Commerce Experience Manager 11.4.0
Weaknesses CWE-200
CWE-284

Thu, 17 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Manipulation in Oracle Commerce Experience Manager 11.4.0
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search / Oracle Commerce Experience Manager
Vendors & Products Oracle commerce Guided Search / Oracle Commerce Experience Manager

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Commerce Guided Search / Oracle Commerce Experience Manager Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T16:50:05.752Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83234

cve-icon Vulnrichment

Updated: 2026-09-21T16:49:59.386Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:35.340

Modified: 2026-09-21T17:19:07.037

Link: CVE-2026-83234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:30:18Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function