Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthorized data access and partial denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, allowing an attacker who can reach the application over HTTP to compromise the system without authentication. Successful exploitation can lead to reading critical data, unauthorized insert, update or delete operations on accessible data, and the ability to induce a partial denial of service affecting application availability. The CVSS 3.1 base score of 7.0 reflects significant impacts on confidentiality and potential disruptions in availability. This vulnerability is a collection of weaknesses including lack of authentication (CWE-306).

Affected Systems

Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 is the sole affected version listed; no other product versions are indicated.

Risk and Exploitability

With a CVSS score of 7.0 the severity is medium‑high, while the EPSS score is less than 1 % indicating a low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the component, requiring no special privileges but still presenting a higher barrier for attackers who can reach the service on the network. Though exploitation is described as difficult, the potential for data exposure and service interruption warrants prompt remediation.

Generated by OpenCVE AI on September 21, 2026 at 21:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a later, non‑affected version that addresses the Forge component vulnerability.
  • Limit external HTTP access to the Oracle Commerce Guided Search component by configuring network firewalls or security groups to allow traffic only from trusted IP ranges.
  • Enforce authentication and HTTPS on all endpoints of Oracle Commerce Guided Search to prevent unauthenticated access.
  • Monitor application and web server logs for anomalous requests and promptly investigate any suspicious activity.

Generated by OpenCVE AI on September 21, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Exposure and Partial Denial of Service in Oracle Commerce Guided Search

Mon, 21 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Forge Component Vulnerability Enables Unauthenticated Data Access and Partial Denial of Service
Weaknesses CWE-200
CWE-285
CWE-400

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Forge Component Vulnerability Enables Unauthenticated Data Access and Partial Denial of Service
Weaknesses CWE-200
CWE-285
CWE-400

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service in Oracle Commerce Guided Search
Weaknesses CWE-200
CWE-285
CWE-400

Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service in Oracle Commerce Guided Search
Weaknesses CWE-200
CWE-285
CWE-400

Wed, 16 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search / Oracle Commerce Experience Manager
Vendors & Products Oracle commerce Guided Search / Oracle Commerce Experience Manager

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Commerce Guided Search / Oracle Commerce Experience Manager Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T17:08:53.949Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83252

cve-icon Vulnrichment

Updated: 2026-09-21T17:08:49.340Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:37.417

Modified: 2026-09-21T18:17:11.197

Link: CVE-2026-83252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:30:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function