ZeroHour

CVE-2026-83249

niche

Local Privilege Escalation to Takeover in Oracle Commerce Guided Search (Forge) 11.4.0

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83249 is a difficult-to-exploit, local privilege escalation flaw in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only version 11.4.0. To trigger it, a low-privileged attacker must already have the ability to log on to the server infrastructure where the product executes, and then perform a series of complex steps (high attack complexity). A successful attack lets the attacker fully compromise the Guided Search / Experience Manager installation, and because the vulnerability changes scope, successful attacks can also significantly impact additional products on the same host. Organizations running Oracle Commerce 11.4.0 with multi-tenant or loosely restricted server access are the most exposed. There is no evidence of exploitation in the wild and no public proof of concept; the flaw was fixed via Oracle's Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83249 if you run Oracle Commerce Guided Search / Experience Manager 11.4.0, and confirm no unsupported Forge builds remain in production. Restrict interactive and service-account logins on hosts running the Forge component to the minimum set of trusted administrators, since exploitation requires local logon with low privileges. Review local account activity, privilege escalations, and unexpected child processes on Forge servers for signs of post-compromise behavior, and isolate these hosts from unrelated workloads given the scope-change risk to additional products.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Forge component)
Estimated exposure
nichelikely low hundreds to a few thousand enterprise deployments worldwide — Oracle Commerce Guided Search is an enterprise-class, on-premises commerce search platform typically deployed by large retailers in dedicated data centers, so deployment counts are far below mass-market software and no public install or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.