CVE-2026-83237: Infoleak
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of Oracle Commerce Guided Search or Oracle Commerce Experience Manager using the Forge component in supported version 11.4.0 are affected. Exploitation is possible over HTTP from the network.
What level of access does an attacker need?
An attacker needs low-privileged access and network access via HTTP. No user interaction is required, and the vulnerability is described as easily exploitable.
What could a successful attacker do?
A successful attack can expose critical data or all data accessible through the affected product. It can also cause a partial denial of service, while integrity impact is not identified in the supplied CVSS vector.