Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker who has already obtained a login to the same infrastructure where Oracle Commerce Guided Search performs to trigger a complete lack of availability. By exploiting a flaw in the Content Acquisition System component, the attacker can cause the application to hang or repeatedly crash. The result is a denial of service for all users interacting with the commerce platform, without any compromise of data confidentiality or integrity.

Affected Systems

Oracle’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. No other versions or product families are listed as impacted in the available data.

Risk and Exploitability

The CVSS 3.1 base score of 6.2 reflects a moderate to high availability impact. The vector AV:L indicates the attacker must have local access, but no elevated privileges are required (PR:N). The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, because it permits a straightforward denial of service once the attacker gains local access, organizations should consider applying an official patch or otherwise mitigating exposure.

Generated by OpenCVE AI on August 2, 2026 at 19:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s issued patch or upgrade to a newer, non‑affected release of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
  • If a patch is not yet available, limit network access to the guided search component so that only trusted hosts or authenticated users can reach it, thereby reducing the opportunity for local exploitation.
  • Deploy monitoring and automated recovery mechanisms such as application performance monitoring, log analysis, and scripted restarts to detect and mitigate hangs or crashes before users are impacted.

Generated by OpenCVE AI on August 2, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Oracle Commerce Guided Search Content Acquisition System Flaw

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Denial of Service via Content Acquisition System Leading to Application Crash
Weaknesses CWE-770

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Denial of Service via Content Acquisition System Leading to Application Crash
Weaknesses CWE-770

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:40:16.443Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61147

cve-icon Vulnrichment

Updated: 2026-07-23T18:40:10.916Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:45:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption