CVE-2026-83235
nicheUnauthenticated Data Exposure in Oracle Commerce Experience Manager 11.4.0
CVE-2026-83235 is an easily exploitable flaw in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only version 11.4.0. An unauthenticated attacker with network access over HTTP can trigger the flaw without user interaction, and successful attacks result in unauthorized access to critical data or complete access to all data reachable by the affected component (high confidentiality impact; integrity and availability are unaffected per the CVSS vector). The vulnerability is scored 7.5 (high) with CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Organizations running Oracle Commerce Guided Search / Experience Manager 11.4.0, particularly deployments where the Experience Manager or related services are reachable from untrusted networks, are affected. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known.
What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83235 to all Oracle Commerce Guided Search / Experience Manager 11.4.0 installations as soon as possible. Until patched, restrict network access to Experience Manager and associated Guided Search endpoints (e.g., admin/tooling ports such as 8888 and MDEX-related services) to trusted hosts or VPN only, and review access logs for unauthenticated requests from unexpected sources. Verify no other supported versions are in use and confirm the fix via Oracle's advisory.
| Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Experience Manager component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.