ZeroHour

CVE-2026-83244

niche

Unauthenticated Adjacent-Network Flaw in Oracle Commerce Guided Search Forge 11.4.0

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83244 is a difficult-to-exploit vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only version 11.4.0. It can be triggered by an unauthenticated attacker who has access to the physical network segment attached to the hardware where the product runs — exploitation is not possible remotely over the internet without that network proximity. A successful attack can give the attacker unauthorized access to critical data or all data accessible to the product, limited unauthorized update, insert, or delete capability, and the ability to cause a complete denial of service (hang or repeatable crash). Organizations running Oracle Commerce Guided Search / Experience Manager 11.4.0 on-premises, particularly where the search tier shares a network segment with less-trusted hosts, are affected. There is no known public proof of concept, the CVE is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83244 to Oracle Commerce Guided Search / Experience Manager 11.4.0 as soon as your patch cycle allows. In the interim, enforce strict network segmentation so only trusted admin and ETL hosts can reach the Forge server's physical segment, since the flaw requires adjacency to exploit. Review logs around the Forge component for unexplained data access, unexpected record modifications, or repeated process hangs/crashes that could indicate an attempted exploit.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge)
Estimated exposure
nichelikely hundreds to a few thousand enterprise deployments worldwide (estimate) — Oracle Commerce Guided Search (formerly Endeca) is an enterprise on-premises commerce search product with no public install counts or dedicated internet-exposure scans, but its use is confined to mid-to-large commerce organizations, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H).

Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H

In the news

No ingested article mentions this CVE yet.