Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Commerce Guided Search / Oracle Commerce Experience Manager product version 11.4.0 contains an access‑control flaw that allows an attacker who can reach the instance over HTTP to retrieve any data exposed by the web application without authentication. This flaw is a confidentiality‑breaking vulnerability; it does not affect integrity or availability but permits an attacker to view the full data set accessible through the application. The vulnerability is mitigated in later releases, so the primary impact is the potential loss of sensitive information to unauthorized parties.

Affected Systems

All installations of Oracle Commerce Guided Search / Oracle Commerce Experience Manager produced by Oracle, specifically those running the 11.4.0 release, are affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 places the flaw in the high severity range. Publicly available exploitation is possible from any network host with HTTP connectivity to the instance, and no authentication or special user privileges are required. The EPSS score is reported as less than 1%, indicating a low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Because the flaw permits full data disclosure, organizations that expose the product to untrusted networks face a serious confidentiality risk if the vulnerability is exploited.

Generated by OpenCVE AI on August 20, 2026 at 19:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle Commerce Guided Search / Experience Manager patch or upgrade to a version newer than 11.4.0 where the access‑control issue has been fixed.
  • Restrict HTTP access to the application by configuring firewalls or network segmentation so that only trusted, internal IP ranges can reach the web interfaces.
  • Enable web‑application firewall rules or logging and monitoring for suspicious or unauthenticated HTTP requests to detect potential exploitation attempts.

Generated by OpenCVE AI on August 20, 2026 at 19:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search / Oracle Commerce Experience Manager
Vendors & Products Oracle commerce Guided Search / Oracle Commerce Experience Manager

Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Disclosure in Oracle Commerce Guided Search / Experience Manager 11.4.0

Thu, 20 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Disclosure in Oracle Commerce Guided Search / Experience Manager 11.4.0

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Allowing Full Data Disclosure in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-200

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Allowing Full Data Disclosure in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Guided Search / Oracle Commerce Experience Manager Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:06:01.593Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:18:03.543

Modified: 2026-08-20T13:08:14.613

Link: CVE-2026-71038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:16:58Z

Weaknesses