Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 and is an access‑control flaw (CWE‑284) that allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data and read data that should not be available. The ability to manipulate or read protected data undermines the integrity and confidentiality of the application’s information. The description explicitly states that the flaw is *easily exploitable* by an attacker with low privileges and HTTP access, indicating that no additional permissions are required beyond the initial network reach.

Affected Systems

Oracle Corporation – Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. The scope change noted in the advisory means that other Oracle Commerce components could also be affected by this access‑control abuse.

Risk and Exploitability

The CVSS base score of 8.5 denotes high severity, while the EPSS score of less than 1 % suggests that exploitation is currently rare or unlikely. Because the attack requires only publicly reachable HTTP access and low privileges, it can be launched from either internal or external networks that can contact the Commerce instance. Despite the low probability of exploitation, the potential impact on confidentiality and integrity is significant enough that the vulnerability is a serious concern. The advisory notes that the issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 20, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Commerce Guided Search / Oracle Commerce Experience Manager patch or upgrade to a fixed release.
  • Restrict HTTP access to the Commerce instance to trusted IP ranges or require VPN connectivity.
  • Implement network segmentation and firewall rules to isolate the Commerce instance from untrusted networks.

Generated by OpenCVE AI on August 20, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Wed, 19 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Commerce Guided Search via HTTP
Weaknesses CWE-639

Wed, 19 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Commerce Guided Search via HTTP
Weaknesses CWE-284
CWE-639

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:08:10.297Z

Reserved: 2026-08-04T22:06:34.611Z

Link: CVE-2026-71002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:59.360

Modified: 2026-08-24T16:43:04.837

Link: CVE-2026-71002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:15:05Z

Weaknesses