Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager lets an attacker with limited local privileges and network connectivity manipulate HTTP requests to access or modify critical data without authorization and can cause the service to crash or hang. The exploit can lead to exposure of confidential information or full denial of service to legitimate clients, affecting both confidentiality and availability but not integrity directly.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. No other product versions or vendor products are listed in the CNA data.

Risk and Exploitability

The CVSS base score of 8.1 indicates a high severity vulnerability. With an AV:N and low attack complexity, an attacker can reach the target over HTTP from an external network. However, the EPSS score of less than 1% suggests that current exploitation attempts are rare. The vulnerability is not in CISA’s KEV catalog. Successful exploitation requires only low privileges and no user interaction, making it potentially easy to achieve in a suitable environment.

Generated by OpenCVE AI on August 4, 2026 at 01:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0.
  • Limit HTTP access to the Commerce Guided Search / Experience Manager endpoints to trusted IP addresses or VPN connections.
  • Enable auditing and log monitoring for abnormal or repeated access attempts to the Guided Search service.

Generated by OpenCVE AI on August 4, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access and Denial of Service in Oracle Commerce Guided Search

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access and Denial of Service in Oracle Commerce Guided Search

Mon, 27 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low‑privileged attacker can compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager, enabling unauthorized data access and denial of service
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑privileged attacker can compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager, enabling unauthorized data access and denial of service
Weaknesses CWE-20
CWE-200
CWE-284
CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:29:55.576Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61160

cve-icon Vulnrichment

Updated: 2026-07-23T18:29:48.946Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption