CVE-2026-83234
nicheUnauthenticated Data Access Flaw in Oracle Commerce Experience Manager 11.4.0
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 contains an easily exploitable vulnerability in the Experience Manager component that allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can result in unauthorized read access to critical data or all data accessible to the product, as well as unauthorized update, insert, or delete access to some of that data. The flaw has a CVSS 3.1 base score of 8.2 (high), with high confidentiality impact and low integrity impact, but no availability impact. Organizations running Oracle Commerce 11.4.0 with the Experience Manager component reachable over the network are affected. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, suggesting no observed in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update (CPU) that addresses CVE-2026-83234 to all Oracle Commerce 11.4.0 installations. Restrict network access to Experience Manager and Guided Search administration endpoints so they are reachable only from trusted internal networks or VPN, since the flaw is exploitable unauthenticated over HTTP. Review HTTP access logs for unauthenticated requests to Experience Manager endpoints to detect any suspicious access or data manipulation.
| Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.