Impact
A vulnerable component in Oracle Commerce Guided Search/Oracle Commerce Experience Manager 11.4.0 allows an unauthenticated attacker with network access over HTTP to compromise the service. The flaw exists in the Forge integration, and a successful exploitation can lead to a full takeover, exposing the application to loss of confidentiality, integrity, and availability. The CVSS v3.1 base score of 8.1 indicates a high‑severity risk with high impact across all three assets.
Affected Systems
Affected systems are Oracle Commerce Guided Search/Oracle Commerce Experience Manager version 11.4.0, as identified by Oracle in its August 2026 security alert. This single version is the only one impacted; no other product iterations or patches are listed.
Risk and Exploitability
The vulnerability is exploitable over the network via standard HTTP (access vector: network), requires no authentication, and can be triggered from any host that can reach the service. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, but the high CVSS base score of 8.1 demonstrates significant potential damage. Oracle does not list it in the CISA KEV catalog, but the lack of a mitigation bulletin and the possibility of remote takeover make it a high‑risk exposure that must be addressed promptly.
OpenCVE Enrichment