Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution and Total Compromise
Action: Immediate Patch
AI Analysis

Impact

This vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker with network access over TCP can exploit a flaw that allows the attacker to compromise the service, leading to a takeover of the application and exposure of confidential, integral, and available data. The impact is broad: an attacker gains full control over the instance, potentially accessing customer data, modifying content, or disrupting service availability. The weakness is an improper access control issue where authentication and authorization checks are insufficient, allowing unrestricted exploitation.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. No other version information is provided. The platform is indexed under the CPE for Oracle Commerce Guided Search/Oracle Commerce Experience Manager 11.4.0 and is a web‑based commerce platform typically deployed on an application server accessible over TCP.

Risk and Exploitability

The vulnerability is exploitable from any network position with TCP access to the application, and the attacker does not need valid credentials, making the attack vector 'Network' with no user interaction. The CVSS score of 8.1 indicates high severity, while the EPSS of less than 1% signifies a low current probability of exploitation, yet the potential damage remains substantial. It is not listed in CISA’s KEV catalog, so no known active exploits are reported at this time. Nonetheless, the full compromise path means organizations should prioritize patching or applying mitigations immediately to prevent potential takeover.

Generated by OpenCVE AI on September 20, 2026 at 08:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the Forge component vulnerability for version 11.4.0
  • Configure network firewalls or access control lists to restrict inbound TCP traffic to the Oracle Commerce service to trusted IP ranges
  • Disable or secure any default or guest access endpoints and enforce authentication to reduce the attack surface before the patch is applied

Generated by OpenCVE AI on September 20, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Network Exploitation in Oracle Commerce Guided Search Leading to Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Leading to Total Compromise of Oracle Commerce Guided Search
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Leading to Total Compromise of Oracle Commerce Guided Search
Weaknesses CWE-284

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search / Oracle Commerce Experience Manager
Vendors & Products Oracle commerce Guided Search / Oracle Commerce Experience Manager

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search / Oracle Commerce Experience Manager Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:40.055Z

Reserved: 2026-08-31T15:40:57.349Z

Link: CVE-2026-83256

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:11.714Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:37.860

Modified: 2026-09-17T14:17:37.980

Link: CVE-2026-83256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management