ZeroHour

CVE-2026-83245

niche

Unauthenticated Takeover Flaw in Oracle Commerce Guided Search Forge Component

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83245 is a difficult-to-exploit, unauthenticated vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting version 11.4.0. It is triggered by an attacker with network access sending crafted HTTP requests to the vulnerable component, without requiring any credentials or user interaction. A successful attack can result in a complete takeover of the Oracle Commerce Guided Search / Experience Manager installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack complexity means exploitation requires conditions outside the attacker's direct control, which lowers practical exploitability somewhat. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, no public proof of concept is known, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83245 to Oracle Commerce Guided Search / Experience Manager 11.4.0 as soon as it is available for your environment. Until patched, restrict network access so the Forge and MDEX components are not reachable from untrusted networks (allow only application-server and administrative traffic). Review HTTP access logs on the affected hosts for unexplained requests targeting the Forge component and verify that dedicated, least-privileged service accounts are in use.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge)
Estimated exposure
niche≈ hundreds to a few thousand enterprise deployments worldwide (order of magnitude ~1,000 instances) — Oracle Commerce Guided Search (formerly Endeca) is a licensed, enterprise-grade on-premises search platform typically deployed by large retailers and B2C sites, so the install base is small and exposure is limited to deployments with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.