CVE-2026-83243
nicheLow-Privilege Data Exposure in Oracle Commerce Experience Manager 11.4.0
CVE-2026-83243 is an easily exploitable information disclosure flaw in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. A remote attacker with only low-privilege (authenticated) access to the product over HTTP can trigger the flaw and gain unauthorized access to critical data, up to complete access to all data reachable by Oracle Commerce Guided Search / Experience Manager. The CVSS 3.1 base score is 7.7 (high), driven by a high confidentiality impact with a scope change, meaning successful attacks may also expose data in additional products beyond the vulnerable component. Organizations running the affected 11.4.0 release of Oracle Commerce Guided Search / Experience Manager are exposed, particularly where low-privilege accounts or the Experience Manager authoring interface are reachable over the network. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that resolves this CVE to Oracle Commerce 11.4.0 as soon as possible. Restrict network access to the Experience Manager authoring/admin interfaces via HTTP to trusted IPs or VPN only, and review low-privilege accounts for necessity and signs of misuse. Audit access logs for unusual reads of sensitive data by low-privilege users, since the flaw may also expose data in products beyond the vulnerable component.
| Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Experience Manager component) | 11.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.