ZeroHour

CVE-2026-83241

niche

Unauthenticated Takeover in Oracle Commerce Guided Search / Experience Manager (Forge) 11.4.0

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83241 is a difficult-to-exploit flaw in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only version 11.4.0. An unauthenticated attacker with network access via HTTP can trigger the flaw, but successful exploitation requires human interaction from someone other than the attacker — for example, tricking a legitimate user into performing an action — which is reflected in the high attack-complexity and UI-required CVSS metrics. A successful attack can result in complete takeover of the Guided Search / Experience Manager deployment, with high impact on confidentiality, integrity, and availability of the commerce search platform and its indexed data. Oracle rates it CVSS 3.1 7.5 (high). No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and no exploitation in the wild is currently known.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates this flaw to Oracle Commerce Guided Search / Experience Manager 11.4.0 as soon as it is released. Restrict HTTP access to Forge and related Guided Search services to trusted internal hosts or VPN ranges, since the attack requires unauthenticated network reachability. Because exploitation depends on victim interaction, brief admins and indexing-pipeline operators on social-engineering risks and review logs for unexpected or anomalous requests against Forge endpoints.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Estimated exposure
nichelikely on the order of hundreds to a few thousand enterprise deployments, with the Forge indexing tier typically internal-facing — Oracle Commerce Guided Search (the former Endeca platform) is a legacy on-premises enterprise product with a small, shrinking retail customer base, and its Forge indexing/ETL component is normally deployed on internal networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.