CVE-2026-83248
nicheUnauthenticated DoS and Data Read in Oracle Commerce Guided Search Forge 11.4.0
Oracle discloses an easily exploitable vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, with supported version 11.4.0 affected. An unauthenticated attacker with network access via HTTP — requiring no privileges or user interaction — can trigger the flaw. Successful exploitation results in unauthorized ability to hang or repeatedly crash the service (complete denial of service) as well as unauthorized read access to a subset of data accessible to the product. The issue carries a CVSS 3.1 base score of 8.2 (high), driven by high availability impact and low confidentiality impact. No public proof of concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses this CVE as soon as possible, as Oracle ships fixes for this product only through its quarterly CPU process. Until patched, restrict HTTP access to Forge and Guided Search / Experience Manager endpoints to trusted hosts using firewall rules or network segmentation. Monitor Forge services for unexplained hangs, crashes, or anomalous data-read requests, and confirm whether version 11.4.0 is deployed in your environment.
| Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager and unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.