ZeroHour

CVE-2026-83248

niche

Unauthenticated DoS and Data Read in Oracle Commerce Guided Search Forge 11.4.0

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

Oracle discloses an easily exploitable vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, with supported version 11.4.0 affected. An unauthenticated attacker with network access via HTTP — requiring no privileges or user interaction — can trigger the flaw. Successful exploitation results in unauthorized ability to hang or repeatedly crash the service (complete denial of service) as well as unauthorized read access to a subset of data accessible to the product. The issue carries a CVSS 3.1 base score of 8.2 (high), driven by high availability impact and low confidentiality impact. No public proof of concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE as soon as possible, as Oracle ships fixes for this product only through its quarterly CPU process. Until patched, restrict HTTP access to Forge and Guided Search / Experience Manager endpoints to trusted hosts using firewall rules or network segmentation. Monitor Forge services for unexplained hangs, crashes, or anomalous data-read requests, and confirm whether version 11.4.0 is deployed in your environment.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge)
Estimated exposure
nichelikely on the order of hundreds to low thousands of enterprise deployments globally — Oracle Commerce Guided Search (formerly Endeca) is legacy enterprise search software with a small and shrinking install base, and its Forge data-processing component is typically deployed on internal networks rather than exposed to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager and unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

In the news

No ingested article mentions this CVE yet.