Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is in the Experience Manager component of Oracle Commerce Guided Search, representing a CWE‑284 authorization violation that allows an unauthenticated attacker with network access via HTTP to create, delete, modify, or read critical data. This results in both confidentiality and integrity compromise of all accessible data within the affected system.

Affected Systems

Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0, used by organizations deploying Oracle’s e‑commerce platform.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 marks this as a high‑severity vulnerability. Although the EPSS score is below 1% and the issue is not currently listed in the CISA KEV catalog, the fact that it can be exploited remotely over HTTP without any authentication means that a determined adversary could cause significant data loss. The attack vector is likely to involve simple HTTP requests sent directly to the exposed service, making it easily exploitable from anywhere on the network.

Generated by OpenCVE AI on August 4, 2026 at 01:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for version 11.4.0 as soon as it is released, which addresses the identified CWE‑284 authorization flaw.
  • Restrict HTTP exposure by placing Oracle Commerce Guided Search / Experience Manager behind a firewall or VPN, limiting access to trusted networks.
  • Enforce strong authentication and monitor authorization logs for suspicious activity, ensuring that data‑modification operations are logged and reviewed.
  • Implement HTTPS for all external communication and ensure that TLS certificates are properly validated to protect data in transit.

Generated by OpenCVE AI on August 4, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification in Oracle Commerce Guided Search/Experience Manager

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification in Oracle Commerce Guided Search/Experience Manager 11.4.0

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification in Oracle Commerce Guided Search/Experience Manager 11.4.0
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:32:22.106Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61153

cve-icon Vulnrichment

Updated: 2026-07-23T18:32:18.783Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses