CVE-2026-83238
nicheAuthenticated Data Exposure and Partial DoS in Oracle Commerce Guided Search (Forge) 11.4.0
CVE-2026-83238 is an easily exploitable flaw in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting version 11.4.0. A low-privileged attacker with network access via HTTP can trigger the flaw to gain unauthorized access to critical data — up to complete access to all data the product can reach — and to cause a partial denial of service. The vulnerability carries a CVSS 3.1 base score of 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L), with high confidentiality and low availability impact and no integrity impact. Organizations running Oracle Commerce (formerly Endeca) search deployments on the affected version are exposed wherever the Forge service is reachable by low-privilege or application-level accounts. There is no evidence of exploitation in the wild: the CVE is not in CISA's KEV catalog and no public proof of concept is known.
What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83238 as soon as possible, as Oracle typically only patches the latest release of this product. Restrict network and HTTP access to the Forge component to trusted administrators and application hosts so low-privilege users cannot reach it. Audit Forge service logs for anomalous data reads or repeated requests indicative of attempted data harvesting or partial DoS.
| Oracle Commerce Guided Search / Commerce Experience Manager (component: Forge) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.