Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw in Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows an attacker with only low privileges and network access over HTTP to perform unauthorized insert, update or delete operations on accessible data, as well as read a subset of that data. The flaw stems from insufficient enforcement of access controls, classified as CWE‑284, and is capable of compromising both the confidentiality and integrity of the system without affecting availability.

Affected Systems

Oracle Corporation’s 11.4.0 release of Oracle Commerce Guided Search / Oracle Commerce Experience Manager is impacted; no other versions or builds are listed as affected.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 base score of 5.4, an EPSS score of less than 1%, and is not listed in the CISA KEV catalog, indicating a low probability of exploitation. However, because the attack requires only basic network connectivity to the application’s HTTP interface and does not demand elevated credentials, a low‑privileged attacker can easily exploit the flaw to compromise data integrity and confidentiality.

Generated by OpenCVE AI on August 4, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle-published patch or upgrade to a version that fixes the authorization flaw in Oracle Commerce Guided Search 11.4.0.
  • Restrict HTTP service access to trusted hosts by implementing firewall rules, VPN gating, or IP whitelisting so that only authorized networks can reach the application’s endpoints.
  • Enforce strict role‑based access control and audit permissions within the application to ensure that only authorized users can perform insert, update, or delete operations.

Generated by OpenCVE AI on August 4, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Authorization flaw in Oracle Commerce Guided Search enabling data modification and disclosure

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Authorization flaw in Oracle Commerce Guided Search enabling data modification and disclosure

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure in Oracle Commerce Guided Search

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure in Oracle Commerce Guided Search

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:54:06.806Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61152

cve-icon Vulnrichment

Updated: 2026-07-23T18:54:00.811Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses