Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Full system compromise (confidentiality, integrity, availability)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker with network connectivity over HTTP can exploit the flaw to compromise the application and ultimately take over the system. The flaw carries a CVSS v3.1 base score of 8.1, indicating significant impacts to confidentiality, integrity and availability.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is affected. No other product versions are mentioned as impacted.

Risk and Exploitability

The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS score and the ability to gain full control make it a high‑severity risk. The attack vector requires network access via HTTP and is inferred from the description; an attacker would need to send crafted requests to the impacted component to trigger the exploitation.

Generated by OpenCVE AI on September 18, 2026 at 19:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle security patch or upgrade to a version newer than 11.4.0 that contains the fix for this vulnerability.
  • Restrict HTTP access to the Oracle Commerce Guided Search component to trusted hosts or networks to prevent unauthenticated traffic.
  • Enforce authentication and proper authorization controls for the component, ensuring that only authorized users can interact with the application.

Generated by OpenCVE AI on September 18, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Full Control of Oracle Commerce Guided Search

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:40.893Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83246

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:26.537Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:36.733

Modified: 2026-09-17T14:17:37.297

Link: CVE-2026-83246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:45:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management