CVE-2026-83255: High severity Oracle Oracle Commerce Guided Search / Oracle Commerce Experience Manager vulnerability
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of Oracle Commerce Guided Search or Oracle Commerce Experience Manager using the Forge component are exposed if they run the affected supported version, 11.4.0, and are reachable by an attacker over TCP.
Does exploitation require an authenticated account or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker with network access via TCP, and it does not require user interaction.
How difficult is exploitation and what could an attacker achieve?
Oracle characterizes exploitation as difficult, reflected by the high attack-complexity rating. A successful attack can result in takeover of the affected product, with high confidentiality, integrity, and availability impact.