Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Apply Fix
AI Analysis

Impact

The vulnerability in Oracle Commerce Guided Search 11.4.0 exposes an improper privilege management weakness (CWE‑269) and improper access control (CWE‑284), allowing an unauthenticated attacker to silently create, delete, or modify critical data. The flaw enables the attacker to read any data managed by the product, resulting in confidentiality and integrity loss. The attack is delivered over HTTP without authentication or UI interaction, and the impact applies to both the Guided Search and Experience Manager components of Oracle Commerce.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 indicates a high severity level with deep confidentiality and integrity impacts. The EPSS score of < 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, an unauthenticated attacker with network access to the HTTP interface can exploit the flaw, making it a significant risk for exposed systems.

Generated by OpenCVE AI on September 23, 2026 at 18:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle security patch or upgrade that addresses this vulnerability; Oracle has not yet released a fixed version for 11.4.0, so monitoring official advisories is essential.
  • Restrict HTTP exposure of the Guided Search interface to trusted internal networks or VPN tunnels to block unauthenticated external requests.
  • Configure the system to enforce proper privilege levels and validate all incoming requests, ensuring that only authenticated, authorized users can perform data‑modification actions (addressing CWE‑269 and CWE‑284).

Generated by OpenCVE AI on September 23, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle Commerce Guided Search 11.4.0

Wed, 23 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search
Weaknesses CWE-269
CPEs cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Guided Search

Fri, 21 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle Commerce Guided Search 11.4.0

Fri, 21 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Unauthorized Data Modification in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Unauthorized Data Modification in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T21:50:13.433Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71036

cve-icon Vulnrichment

Updated: 2026-08-20T18:59:42.643Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:03.313

Modified: 2026-09-23T17:33:59.600

Link: CVE-2026-71036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T19:00:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control