Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. It permits a low‑privileged attacker who can send HTTP traffic over the network to trigger code execution on the server, effectively giving the attacker full control over the application and compromising confidentiality, integrity and availability. The CVSS 3.1 Base Score of 9.9 and the scope change flag indicate a critical impact that can extend beyond the directly affected component.

Affected Systems

Oracle Commerce Guided Search and Oracle Commerce Experience Manager running release 11.4.0 are listed as vulnerable. The advisory notes that because the vulnerability changes scope, additional Oracle Commerce products may also be affected, although only this version is explicitly identified.

Risk and Exploitability

The EPSS score of less than 1 % indicates that exploit attempts are statistically rare, but the very high CVSS score means a single successful attack would be devastating. The flaw is not reported in CISA’s KEV catalog. Attackers only need network access over HTTP; no special privileges or credentials are required beyond being a low‑privileged user with the ability to craft the HTTP request.

Generated by OpenCVE AI on August 4, 2026 at 16:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle-released patch or upgrade to a non‑vulnerable release of Oracle Commerce Guided Search or Oracle Commerce Experience Manager.
  • Restrict HTTP traffic to the application by allowing only trusted IP addresses or subnets to reach the affected services.
  • If a patch is not yet available, disable or block the Content Acquisition System component until a fix is deployed.

Generated by OpenCVE AI on August 4, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Content Acquisition System in Oracle Commerce 11.4.0

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Content Acquisition System in Oracle Commerce 11.4.0

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote code execution in Oracle Commerce Guided Search via low‑privileged HTTP
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote code execution in Oracle Commerce Guided Search via low‑privileged HTTP
Weaknesses CWE-269
CWE-284
CWE-285
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:41:01.364Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61146

cve-icon Vulnrichment

Updated: 2026-07-23T18:40:57.727Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function