Impact
The vulnerability is a weak access control flaw (CWE-284) in the Content Acquisition System of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. An unauthenticated attacker with network access via HTTP can exploit the flaw to create, delete, or modify critical data, and to cause a hang or repeatable crash that results in full denial of service. This bypasses normal authentication controls and enables unrestricted use of the system’s data and functions.
Affected Systems
This issue affects Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0. Oracle issued a security advisory (https://www.oracle.com/security-alerts/cspuaug2026.html) for the affected product.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 classifies this as a critical flaw, indicating severe integrity and availability impacts. The EPSS score is < 1%, suggesting a very low but nonzero probability of exploitation; however, the lack of authentication and low complexity suggest that it could be exploitable by a broad audience. The vulnerability is not listed in the CISA KEV catalog, but its high severity and remote nature warrant immediate attention. The likely attack vector is remote, over HTTP traffic, through the insecure access control in the Content Acquisition System.
OpenCVE Enrichment