Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Breach
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows a low‑privileged attacker with network access to the HTTP interface to obtain unauthorized access to critical data. A successful exploitation can result in the attacker gaining read access to all data exposed by the product, representing a high impact on confidentiality. The weakness is consistent with improper access control, enabling data exposure without authentic privileges and potentially affecting other products due to the scope change noted in the CVSS vector.

Affected Systems

Oracle Corporation’s Oracle Commerce 11.4.0 is affected. No other versions or components are listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 indicates a high severity with high confidentiality impact and a scope change. The EPSS score of less than 1% shows exploit probability is currently low, and the vulnerability is not yet listed in CISA’s KEV catalog. The apparent attack vector is network‑based via HTTP, and the attack requires only low privilege, so an adversary with remote access could potentially exploit the flaw without higher‑level credentials. This combination of high severity and low exploitation probability suggests that while the risk is significant, active exploitation is currently unlikely unless the vendor issues a patch.

Generated by OpenCVE AI on September 21, 2026 at 18:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy the vendor’s security patch or update for Oracle Commerce Guided Search 11.4.0 as provided in the Oracle security alert linked above.
  • Restrict network access to the Oracle Commerce Guided Search HTTP interface by configuring firewall rules or placing it behind a secure proxy to limit exposure to trusted hosts.
  • If the vendor has not yet released a patch, temporarily disable or remove the Guided Search functionality until the fix is deployed to eliminate the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Guided Search 11.4.0 Remote Access Data Exposure

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Guided Search 11.4.0 Remote Access Data Exposure
Weaknesses CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access due to Improper Access Control in Oracle Commerce Guided Search
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access due to Improper Access Control in Oracle Commerce Guided Search
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T17:00:42.297Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83243

cve-icon Vulnrichment

Updated: 2026-09-21T17:00:37.795Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:36.353

Modified: 2026-09-21T17:19:07.717

Link: CVE-2026-83243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T18:45:18Z

Weaknesses