Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, found in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component, allows an attacker with high privileges but only network access via HTTP to take control of the application. Successful exploitation can lead to unauthorized access to critical data or full access to all data managed by the product. The vulnerability is considered easily exploitable and is identified by CVSS 3.1 with an AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N score of 6.8.

Affected Systems

Affected systems include Oracle Corporation's Oracle Commerce Guided Search and Oracle Commerce Experience Manager 11.4.0. No other product versions are listed as impacted, but the description indicates that attacks may change scope to affect additional products.

Risk and Exploitability

The CVSS base score of 6.8 reflects a moderate severity with a confidentiality impact. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Due to the network-based attack vector over HTTP and the requirement of high-level privileges, the risk is moderate; however, the potential for scope change increases the threat if an attacker can leverage the vulnerability to move laterally within the organization.

Generated by OpenCVE AI on August 19, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses CVE-2026-71007 as soon as it is released
  • Restrict HTTP access to the Commerce Guided Search web interface to trusted internal networks and enforce strict authentication
  • Enable and monitor audit logging for unauthorized access attempts and review logs regularly for anomalies

Generated by OpenCVE AI on August 19, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Access Vulnerability in Oracle Commerce Guided Search

Wed, 19 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Access Vulnerability in Oracle Commerce Guided Search
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:07:41.580Z

Reserved: 2026-08-04T22:06:34.611Z

Link: CVE-2026-71007

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:59.947

Modified: 2026-08-24T16:31:31.040

Link: CVE-2026-71007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T22:00:08Z

Weaknesses