Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows an unauthenticated attacker who has access to the underlying infrastructure to compromise the component. The flaw is a local privilege escalation that requires the attacker to obtain user interaction from a person other than the attacker. Successful exploitation can lead to full takeover of the product, resulting in loss of confidentiality, integrity, and availability, as indicated by the CVSS 3.1 score of 7.8.

Affected Systems

The affected products are Oracle Commerce Guided Search and Oracle Commerce Experience Manager from Oracle Corporation, specifically version 11.4.0. Deployments running this version are potentially vulnerable.

Risk and Exploitability

A CVSS 3.1 base score of 7.8 indicates a high impact vulnerability. The vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) shows that the flaw is exploitable with local access to the infrastructure where Oracle Commerce Guided Search/Experience Manager runs, without requiring authentication to the application, but manual interaction from a user other than the attacker is required. EPSS is below 1%, implying a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local exploitation by an attacker with infrastructure access who then persuades or coaxes a legitimate user to trigger the vulnerable code.

Generated by OpenCVE AI on August 20, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle Commerce Guided Search / Oracle Commerce Experience Manager released by Oracle
  • Restrict local access to the servers hosting the Oracle Commerce components, enforcing least privilege principles
  • Enable logging and monitoring of UIs and API calls on the Commerce platform to detect anomalous activity

Generated by OpenCVE AI on August 20, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Thu, 20 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local privilege escalation in Oracle Commerce Guided Search enabling takeover with user interaction

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Privilege Escalation in Oracle Commerce Guided Search 11.4.0

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Privilege Escalation in Oracle Commerce Guided Search 11.4.0

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Compromise of Oracle Commerce Experience Manager
Weaknesses CWE-284
CWE-862

Wed, 19 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Compromise of Oracle Commerce Experience Manager
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:07:22.059Z

Reserved: 2026-08-04T22:06:34.611Z

Link: CVE-2026-71010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:00.310

Modified: 2026-08-24T16:31:11.140

Link: CVE-2026-71010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:15:05Z

Weaknesses