Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows a low‑privileged attacker who can reach the system over HTTP to bypass authentication and authorization controls, resulting in arbitrary code execution and a complete takeover of the application. This leads to a loss of confidentiality, integrity, and availability, giving the attacker full control over the hosted site and its data.

Affected Systems

Oracle Commerce Guided Search 11.4.0 and Oracle Commerce Experience Manager 11.4.0 are the only versions listed as affected. No other product variants or versions are identified as impacted in the advisory.

Risk and Exploitability

The CVSS base score of 8.8 reflects a high impact across confidentiality, integrity, and availability. An EPSS score of < 1 % indicates the likelihood of exploitation is very low at present, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is network‑based via standard HTTP traffic and requires only low privileged access; any host that can reach the exposed endpoints could be compromised. The overall risk is moderate to high, with a low expected exploitation probability, so timely patching is strongly recommended.

Generated by OpenCVE AI on August 4, 2026 at 01:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Oracle security bulletin for the latest patch for Oracle Commerce Guided Search / Experience Manager 11.4.0 and apply the recommended update or upgrade to a supported version that contains the fix.
  • If an immediate patch is unavailable, restrict network access to the application by allowing only trusted IP addresses through firewall rules or an application gateway.
  • Disable or block the vulnerable HTTP endpoints tied to the Experience Manager component as a temporary workaround until patch deployment is complete.

Generated by OpenCVE AI on August 4, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Authentication and Authorization Flaw Enables Full Takeover of Oracle Commerce Guided Search

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Authentication and Authorization Flaw Enables Full Takeover of Oracle Commerce Guided Search

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Commerce Guided Search Leading to Application Takeover
Weaknesses CWE-94

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Commerce Guided Search Leading to Application Takeover
Weaknesses CWE-94

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:39:00.302Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61149

cve-icon Vulnrichment

Updated: 2026-07-23T18:38:56.197Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function