Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the Forge component of Oracle Commerce Guided Search/Experience Manager allows a low‑privileged attacker who can reach the service over HTTP to bypass authentication checks. The vulnerability can lead to unauthorized reading of critical data, full access to all data exposed by the Commerce solution, and the ability to cause a partial denial of service by disrupting application functionality. It is a classic authentication bypass and access control weakness.

Affected Systems

Affected systems are Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other product variants or versions are reported by the CNA.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 classifies this issue as medium‑high risk, requiring only network access, low attack complexity, and low privileges. The EPSS score below 1% indicates that exploitation is predicted to be rare, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated HTTP requests to the affected Forge component, meaning exposed instances are at significant risk if not patched.

Generated by OpenCVE AI on September 20, 2026 at 08:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch to Oracle Commerce Guided Search version 11.4.0 to eliminate the authentication bypass.
  • Restrict HTTP access to the Commerce servers to trusted IP ranges or a VPN to reduce exposure.
  • Deploy a web‑application firewall or similar monitoring that flags anomalous authentication requests and blocks suspected exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle Commerce Guided Search/Experience Manager Enabling Unauthorized Data Access and Partial Denial of Service
Weaknesses CWE-200

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle Commerce Guided Search Forge Component
Weaknesses CWE-284
CWE-287

Wed, 16 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle Commerce Guided Search Forge Component
Weaknesses CWE-284
CWE-287

Wed, 16 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search / Oracle Commerce Experience Manager
Vendors & Products Oracle commerce Guided Search / Oracle Commerce Experience Manager

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Commerce Guided Search / Oracle Commerce Experience Manager Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T16:58:10.839Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83238

cve-icon Vulnrichment

Updated: 2026-09-21T16:58:03.155Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:35.800

Modified: 2026-09-21T17:19:07.490

Link: CVE-2026-83238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor