Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager 11.4.0 allows an attacker with low privileges and network access via HTTP to read or modify critical data. The flaw results in confidentiality loss, with high impact on sensitive data, while integrity is affected at a low level. The CVSS score of 7.1 indicates a high severity of this permission escalation.

Affected Systems

The issue is limited to Oracle Corporation's Oracle Commerce Guided Search and Oracle Commerce Experience Manager products, specifically version 11.4.0.

Risk and Exploitability

Despite an EPSS score of less than 1%, the vulnerability is easily exploitable over a network using HTTP when the attacker has minimal privileges. The lack of a KEV designation does not reduce its potential risk; attackers could exploit the flaw to gain read, insert, or delete access to data owned by the Commerce platform. If left unpatched, the attack surface remains active for anyone who can reach the exposed HTTP interface.

Generated by OpenCVE AI on August 4, 2026 at 01:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE-2026-61151 to version 11.4.0 or later
  • Restrict inbound HTTP access to the Commerce Experience Manager by using firewalls or access control lists
  • Audit and monitor recent changes to data accessed through the Commerce platform for suspicious activity

Generated by OpenCVE AI on August 4, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege Network Exploit in Oracle Commerce Guided Search 11.4.0

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege Network Exploit in Oracle Commerce Guided Search 11.4.0

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Commerce Guided Search via Low-Privilege HTTP Attack

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search And Experience Manager
Vendors & Products Oracle commerce Guided Search And Experience Manager

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Commerce Guided Search via Low-Privilege HTTP Attack

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager Commerce Guided Search And Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:31:31.881Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61151

cve-icon Vulnrichment

Updated: 2026-07-23T18:31:28.048Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses