Executive brief
A critical vulnerability has been identified in Oracle Commerce Guided Search and Experience Manager, specifically within the Content Acquisition System component. This software is used by businesses to manage product search and customer experiences on e-commerce platforms. An attacker could exploit this flaw to gain full control over the system, potentially leading to the theft of sensitive data, disruption of online sales, and complete loss of service availability.
Technical details
A vulnerability in the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows for complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected environment. While the specific vulnerability class (e.g., RCE, Auth Bypass) is not explicitly named in the advisory, the CVSS score of 9.8 and the 'takeover' description indicate a critical failure in access control or input validation. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed: CVE-2026-61145 was published to the NVD.