Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Full system takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an attacker who can log on to the underlying infrastructure – but is otherwise unauthenticated against the application – to compromise the application. The vulnerability requires a human user other than the attacker to interact with the compromised component, after which attacker-controlled code can be executed, leading to a complete takeover. The flaw exposes the application to simultaneous confidentiality, integrity, and availability disruptions, with the stated CVSS vector indicating high impact on all three submetrics.

Affected Systems

Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is the only identified affected build. No other Oracle Commerce versions are listed as impacted.

Risk and Exploitability

The CVSS base score of 7.8 classifies this issue as high risk. The EPSS score of less than 1% implies a low likelihood of industrial exploitation at present, and it is not featured in the CISA KEV catalog. However, because successful exploitation still requires a person outside the attacker to interact with the system, an attacker who can compromise the underlying infrastructure—e.g., via a compromised administrator account—could leverage this weakness. Organizations operating at least version 11.4.0 should treat this as a high-priority vulnerability and consider it in their overall risk posture.

Generated by OpenCVE AI on September 20, 2026 at 08:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or upgrade to a version that does not contain the affected Forge component.
  • If a patch is not available, restrict network access to the application server to a tight set of trusted IPs to ensure that only authorized users can log on.
  • Disable or remove the Forge component if it is not required for business processes.
  • Continuously monitor server logs for unauthorized logon attempts and suspicious activity around the Forge functionality.

Generated by OpenCVE AI on September 20, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Attack Requires Human Interaction to Compromise Oracle Commerce Guided Search

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Infrastructure Access Enables Takeover of Oracle Commerce Guided Search
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Infrastructure Access Enables Takeover of Oracle Commerce Guided Search
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:40.689Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83247

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:23.628Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:36.853

Modified: 2026-09-17T14:17:37.410

Link: CVE-2026-83247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management