CVE-2026-83256: High severity Oracle Oracle Commerce Guided Search / Oracle Commerce Experience Manager vulnerability
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with network access over TCP can attempt exploitation. No user interaction or prior privileges are required, although exploitation is rated difficult.
Which deployment is known to be affected?
The affected supported version identified is Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0, specifically the Forge component.
What is the potential impact of a successful attack?
Successful exploitation can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, with high impacts to confidentiality, integrity, and availability.