ZeroHour

CVE-2026-83242

niche

Unauthenticated Data Manipulation Flaw in Oracle Commerce Experience Manager 11.4.0

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83242 is a high-severity (CVSS 7.3) vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting the supported version 11.4.0. It is easily exploitable by an unauthenticated attacker with network access over HTTP, requiring no privileges or user interaction. A successful attack lets the attacker gain unauthorized update, insert, and delete access to some of the product's accessible data, unauthorized read access to a subset of that data, and the ability to cause a partial denial of service. Organizations running the affected on-premises commerce search/personalization product are exposed wherever its HTTP endpoints are reachable, particularly if the Experience Manager interface is internet-facing. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this issue to all Oracle Commerce Guided Search / Experience Manager 11.4.0 deployments as soon as it is available. In the interim, restrict network access to Experience Manager and related HTTP endpoints (e.g., via firewall rules or VPN) so they are not reachable from untrusted networks, and inspect access logs for unauthenticated requests targeting the Experience Manager component. Verify that no other Oracle Commerce deployments in your environment are running the affected 11.4.0 version.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Experience Manager)
Estimated exposure
nichelikely on the order of hundreds to low thousands of enterprise deployments — Oracle Commerce Guided Search / Experience Manager (the former Endeca platform) is a legacy enterprise commerce search product deployed on-premises by large retailers and B2B sites rather than a mass-market product, and no public scan or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.