ZeroHour

CVE-2026-83243

niche

Low-Privilege Data Exposure in Oracle Commerce Experience Manager 11.4.0

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83243 is an easily exploitable information disclosure flaw in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. A remote attacker with only low-privilege (authenticated) access to the product over HTTP can trigger the flaw and gain unauthorized access to critical data, up to complete access to all data reachable by Oracle Commerce Guided Search / Experience Manager. The CVSS 3.1 base score is 7.7 (high), driven by a high confidentiality impact with a scope change, meaning successful attacks may also expose data in additional products beyond the vulnerable component. Organizations running the affected 11.4.0 release of Oracle Commerce Guided Search / Experience Manager are exposed, particularly where low-privilege accounts or the Experience Manager authoring interface are reachable over the network. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that resolves this CVE to Oracle Commerce 11.4.0 as soon as possible. Restrict network access to the Experience Manager authoring/admin interfaces via HTTP to trusted IPs or VPN only, and review low-privilege accounts for necessity and signs of misuse. Audit access logs for unusual reads of sensitive data by low-privilege users, since the flaw may also expose data in products beyond the vulnerable component.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Experience Manager component)11.4.0
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (estimate) — Oracle Commerce Guided Search/Experience Manager is enterprise commerce (search/merchandising) software deployed at large retailers rather than a mass-market product, and no public install counts or internet-exposure scan data are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.