Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Content Acquisition System of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An attacker who can reach the application over HTTP can bypass normal authentication and retrieve confidential data or, in the worst case, all data managed by the system. The flaw is assigned a CVSS 3.1 base score of 6.8, indicating a moderate threat to confidentiality but no direct impact on integrity or availability.

Affected Systems

Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is the only clearly affected version listed in the CNA data. No other product releases are mentioned as vulnerable.

Risk and Exploitability

The CVSS score indicates moderate severity, and the EPSS score of <1% suggests that the probability of active exploitation is very low. The vulnerability is not currently included in the CISA KEV catalog, and there is no evidence of widespread attacks. However, the attack vector is network‑based over HTTP without any authentication, which provides a relatively straightforward entry point. A successful exploitation could compromise confidentiality and, due to the scope change flag, potentially expose adjacent Oracle Commerce components.

Generated by OpenCVE AI on August 22, 2026 at 08:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses CVE-2026-70990 for Oracle Commerce Guided Search / Oracle Commerce Experience Manager
  • Configure network firewalls or IP whitelisting to limit HTTP access to the Commerce Guided Search endpoints so only trusted hosts can reach the application
  • Review and tighten the permissions of the Content Acquisition System, ensuring that only authorized roles can read data, and disable public access if not required

Generated by OpenCVE AI on August 22, 2026 at 08:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Sat, 22 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exposes Sensitive Data in Oracle Commerce Guided Search

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Unauthorized Data Exposure in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-285
CWE-286

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Unauthorized Data Exposure in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-285
CWE-286

Thu, 20 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Compromise of Oracle Commerce Guided Search
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Compromise of Oracle Commerce Guided Search
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:43:53.091Z

Reserved: 2026-08-04T22:06:34.610Z

Link: CVE-2026-70990

cve-icon Vulnrichment

Updated: 2026-08-22T03:43:48.061Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:57.980

Modified: 2026-08-24T16:31:59.413

Link: CVE-2026-70990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor