Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server Compromise
Action: Patch Immediately
AI Analysis

Impact

Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is impacted by a difficult-to-exploit vulnerability that permits an unauthenticated attacker with network access via TCP to take full control of the application. Successful exploitation results in a complete takeover, compromising confidentiality, integrity, and availability of the system. The weakness can be categorized as an improper authentication flaw, allowing attackers to bypass authentication controls and gain unrestricted access.

Affected Systems

The affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically the 11.4.0 release. No other versions or components are currently listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 signals high severity, with full disclosure of confidentiality, integrity, and availability impacts. The EPSS score of less than 1% indicates a very low but non-zero probability of exploitation at the time of analysis. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities catalog. Attackers can remotely exploit this weakness over the network without authentication, making it a high-risk scenario for exposed instances.

Generated by OpenCVE AI on September 18, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the authentication bypass in Oracle Commerce Guided Search 11.4.0
  • Restrict network exposure of the Oracle Commerce service by limiting inbound TCP connections to trusted hosts or networks
  • Reconfigure the application to enforce strong authentication mechanisms and remove any legacy or default credentials

Generated by OpenCVE AI on September 18, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Commerce Guided Search 11.4.0

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-287

Wed, 16 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search / Oracle Commerce Experience Manager
Vendors & Products Oracle commerce Guided Search / Oracle Commerce Experience Manager

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search / Oracle Commerce Experience Manager Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:40.377Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83254

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:17.964Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:37.643

Modified: 2026-09-17T14:17:37.753

Link: CVE-2026-83254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:30:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication