Junglewise Threat Intelligence

CVE-2026-61146: Oracle Commerce Guided Search compromise in Content Acquisition System

CVE-2026-61146 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle Commerce Guided Search and Experience Manager, tools used by businesses to manage product discovery and customer experiences on e-commerce platforms. An attacker with low-level access to the network can exploit this flaw to take full control of the system. This could lead to the theft of sensitive customer data, disruption of online sales operations, and potential unauthorized access to other connected corporate systems.

Technical details

This vulnerability affects the Content Acquisition System (CAS) component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows for a complete takeover of the affected product (Confidentiality, Integrity, and Availability impact). Notably, the vulnerability includes a 'scope change' (S:C), meaning a successful exploit can impact security beyond the immediate Oracle Commerce environment, potentially affecting other integrated products or the underlying infrastructure. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats