Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 and allows an unauthenticated attacker with network access via HTTP to gain unauthorized update, insert, delete, or read operations on data that the product exposes. This leads to confidentiality and integrity impacts as stated in the CVSS 3.1 vector, while availability is not affected.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0. No other versions or products are listed as impacted in the current data.

Risk and Exploitability

The CVSS base score of 6.1 describes moderate severity. EPSS score of 0.00181 (<1%) indicates a very low exploitation probability, and the vulnerability is not yet listed in CISA KEV. Based on the description, the likely attack vector is an unauthenticated HTTP request; successful exploitation also requires a human interaction from a person other than the attacker, and the scope change indicates that additional related products could be affected by a successful exploit.

Generated by OpenCVE AI on August 19, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Commerce security patch or upgrade to a version that does not contain the 11.4.0 vulnerability.
  • Restrict HTTP access to the Oracle Commerce Guided Search / Experience Manager to trusted network segments and enforce strict firewall rules.
  • Ensure that only authenticated and authorized users can perform update, insert, or delete operations; review and tighten role‑based access controls.
  • Set up monitoring and logging for anomalous data modification or read attempts on the product.

Generated by OpenCVE AI on August 19, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Unauthorized Data Modification in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:01:10.309Z

Reserved: 2026-08-04T22:06:34.611Z

Link: CVE-2026-71011

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:16.991Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:00.420

Modified: 2026-08-24T17:15:50.697

Link: CVE-2026-71011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T15:15:05Z

Weaknesses