ZeroHour

CVE-2026-83252

niche

Unauthenticated data-access flaw in Oracle Commerce Guided Search (Forge), v11.4.0

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83252 is a difficult-to-exploit, unauthenticated vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only the supported version 11.4.0. An attacker with network access via HTTP, without credentials or user interaction, can trigger the flaw, though the high attack complexity (AC:H) means special conditions or timing are likely required. Successful exploitation allows the attacker to read critical data or all data accessible to the product, to insert, update, or delete some of that data, and to cause a partial denial of service. Organizations running Oracle Commerce Guided Search / Experience Manager 11.4.0 with the Forge pipeline component reachable over the network are affected. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83252 to all Oracle Commerce Guided Search / Experience Manager 11.4.0 installations. Until patched, restrict network access so the Forge and related Endeca pipeline services are reachable only from trusted hosts, and monitor HTTP access logs for unauthenticated or anomalous requests. Review indexing pipeline outputs and application data for signs of unauthorized reads, tampering, or partial denial of service.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge)
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (estimate) — Oracle Commerce Guided Search (formerly Endeca) is an enterprise-only commerce search platform with no public install counts, typically deployed by large retailers inside perimeter networks rather than exposed at scale, so the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.