Description
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Commerce Guided Search Platform Services 11.4.0 contains an unauthenticated vulnerability in the Forge component that permits attackers to create, delete, or modify critical data and read all data exposed by the service over HTTPS. The flaw directly compromises confidentiality and integrity, classifying it as a high‑impact access control weakness (CWE‑284).

Affected Systems

Systems that run Oracle Commerce Guided Search Platform Services version 11.4.0 and expose the service over HTTPS are affected. No other versions or products are currently known to be impacted.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 marks the vulnerability as Critical, while the EPSS score of less than 1% and the absence from the CISA KEV catalog indicate a low current exploitation probability. An external attacker can exploit the flaw simply by sending unauthenticated HTTPS requests to the exposed service, bypassing all authentication checks and executing arbitrary data manipulation or exfiltration requests.

Generated by OpenCVE AI on August 4, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Oracle patch for Oracle Commerce Guided Search Platform Services 11.4.0 as published in the official security advisory.
  • Restrict direct external HTTPS access to the service by placing it behind a firewall, VPN, or limiting IP ranges until the patch is applied.
  • Enable detailed logging of all REST API requests and monitor for abnormal POST, PUT, DELETE, or GET actions that may indicate exploitation.
  • Verify that authentication is enforced on the service by testing with known credentials; if authentication is disabled, enforce proper access controls.

Generated by OpenCVE AI on August 4, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Manipulation via HTTPS in Oracle Commerce Guided Search Platform Services

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Guided Search Platform Services 11.4.0 Unauthenticated Data Manipulation via HTTPS

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Guided Search Platform Services 11.4.0 Unauthenticated Data Manipulation via HTTPS

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Control in Oracle Commerce Guided Search 11.4.0

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Control in Oracle Commerce Guided Search 11.4.0

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle commerce Guided Search Platform Services
CPEs cpe:2.3:a:oracle:commerce_guided_search_platform_services:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search Platform Services
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Commerce Guided Search Platform Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:36:18.421Z

Reserved: 2026-07-08T15:52:20.737Z

Link: CVE-2026-61156

cve-icon Vulnrichment

Updated: 2026-07-23T18:35:55.436Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses