ZeroHour

CVE-2026-83246

niche

Unauthenticated Takeover in Oracle Commerce Guided Search (Forge) 11.4.0

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

A vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated remote attacker with HTTP network access to fully compromise the affected product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Oracle rates the vulnerability as difficult to exploit (attack complexity: high), meaning an attacker would need favorable conditions or significant preparation, but no authentication, user interaction, or privileges are required. Successful exploitation results in complete takeover of the Guided Search / Experience Manager installation. Only the supported version 11.4.0 is listed as affected. There is no known public proof of concept, no confirmed in-the-wild exploitation, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83246 to all Oracle Commerce Guided Search / Experience Manager 11.4.0 installations as soon as it is available. Verify that Forge and other backend Guided Search services are not exposed to the public internet or untrusted networks — restrict access via firewall rules to known indexing and application hosts. Monitor HTTP access logs to Forge endpoints for unexpected unauthenticated requests and anomalous behavior until the patch is applied.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge)
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide, with only a small subset of Forge endpoints reachable directly from the internet — Oracle Commerce Guided Search (formerly Endeca) is enterprise-only commerce search software typically deployed at large retailers, and Forge is a backend indexing component usually run on internal networks rather than internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.