Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search/Experience Manager. A low‑privileged attacker with network access over HTTP can exploit the flaw to gain unauthorized access to all data that the product can retrieve. The vulnerability permits disclosure of confidential information without any user interaction and represents a classic case of improper authorization (CWE‑284).

Affected Systems

Affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager from Oracle Corporation, version 11.4.0. No other versions are listed as impacted.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 reflects a high‑severity risk with confidentiality impact only. The attack vector is via network and requires low privileges; there is no user interaction. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Given the ease of exploitation from a remote HTTP connection, an attacker that can reach the target network could potentially compromise the product, and the known scope change means additional products in the environment may be vulnerable as well.

Generated by OpenCVE AI on August 20, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to the fixed version as issued in the official advisory
  • Restrict HTTP access to the product to trusted IP ranges or networks using firewall or access control lists
  • Monitor logs for anomalous search requests or repeated failed attempts
  • If a patch is not available, disable or isolate the Content Acquisition System component until a fix is released

Generated by OpenCVE AI on August 20, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Thu, 20 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Commerce Guided Search via HTTP

Thu, 20 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Network Exploitable Vulnerability in Oracle Commerce Guided Search Allowing Unauthorized Data Access
Weaknesses CWE-285

Wed, 19 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Network Exploitable Vulnerability in Oracle Commerce Guided Search Allowing Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:08:46.187Z

Reserved: 2026-08-04T22:06:34.610Z

Link: CVE-2026-70988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:57.753

Modified: 2026-08-24T16:43:28.037

Link: CVE-2026-70988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:15:05Z

Weaknesses