ZeroHour

CVE-2026-83235

niche

Unauthenticated Data Exposure in Oracle Commerce Experience Manager 11.4.0

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83235 is an easily exploitable flaw in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only version 11.4.0. An unauthenticated attacker with network access over HTTP can trigger the flaw without user interaction, and successful attacks result in unauthorized access to critical data or complete access to all data reachable by the affected component (high confidentiality impact; integrity and availability are unaffected per the CVSS vector). The vulnerability is scored 7.5 (high) with CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Organizations running Oracle Commerce Guided Search / Experience Manager 11.4.0, particularly deployments where the Experience Manager or related services are reachable from untrusted networks, are affected. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83235 to all Oracle Commerce Guided Search / Experience Manager 11.4.0 installations as soon as possible. Until patched, restrict network access to Experience Manager and associated Guided Search endpoints (e.g., admin/tooling ports such as 8888 and MDEX-related services) to trusted hosts or VPN only, and review access logs for unauthenticated requests from unexpected sources. Verify no other supported versions are in use and confirm the fix via Oracle's advisory.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Experience Manager component)
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide, only a subset internet-exposed — Oracle Commerce (formerly ATG/Endeca) is legacy enterprise e-commerce and guided-search software with a small, shrinking installed base that is typically deployed behind perimeter controls rather than internet-facing.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.