Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, the Experience Manager component contains an access‑control flaw that permits low‑privileged users who can reach the HTTP interface to perform privileged operations. Successful exploitation allows an attacker to take complete control of the application, resulting in confidentiality, integrity, and availability impacts. This flaw is classified as improperly controlled access to privileged functions (CWE‑284).

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager products, specifically version 11.4.0, are affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers only require network connectivity to the HTTP interface and a low‑privileged account. Once exploited, they can gain full application control, potentially exposing sensitive business data and disrupting commerce operations.

Generated by OpenCVE AI on August 4, 2026 at 01:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Commerce patch or upgrade to a non‑affected release such as 11.4.1 or later.
  • Restrict network access to the Guided Search / Experience Manager component by using firewalls or ACLs, allowing only trusted internal hosts and privileged roles.
  • Enforce proper application‑level access controls, ensuring that low‑privileged users cannot perform privileged actions and regularly review ACLs and audit logs for suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Takeover in Oracle Commerce Guided Search

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Takeover in Oracle Commerce Guided Search

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit Allows Full Takeover of Oracle Commerce Guided Search

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search And Experience Manager
Vendors & Products Oracle commerce Guided Search And Experience Manager

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit Allows Full Takeover of Oracle Commerce Guided Search

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager Commerce Guided Search And Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:39:40.786Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61148

cve-icon Vulnrichment

Updated: 2026-07-23T18:39:37.953Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses