CVE-2026-83245
nicheUnauthenticated Takeover Flaw in Oracle Commerce Guided Search Forge Component
CVE-2026-83245 is a difficult-to-exploit, unauthenticated vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting version 11.4.0. It is triggered by an attacker with network access sending crafted HTTP requests to the vulnerable component, without requiring any credentials or user interaction. A successful attack can result in a complete takeover of the Oracle Commerce Guided Search / Experience Manager installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack complexity means exploitation requires conditions outside the attacker's direct control, which lowers practical exploitability somewhat. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, no public proof of concept is known, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83245 to Oracle Commerce Guided Search / Experience Manager 11.4.0 as soon as it is available for your environment. Until patched, restrict network access so the Forge and MDEX components are not reachable from untrusted networks (allow only application-server and administrative traffic). Review HTTP access logs on the affected hosts for unexplained requests targeting the Forge component and verify that dedicated, least-privileged service accounts are in use.
| Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.