Junglewise Threat Intelligence

CVE-2026-61147: Oracle Commerce Guided Search denial of service in Content Acquisition System

CVE-2026-61147 · Severity: medium · CVSS 6.2 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A denial-of-service vulnerability exists in Oracle Commerce Guided Search and Experience Manager, tools used by businesses to manage site search and customer experiences. An attacker with access to the underlying server can cause the application to hang or crash repeatedly. This can lead to significant service outages, preventing customers from searching for products or accessing digital storefront content.

Technical details

A vulnerability in the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) allows for a complete denial of service. The flaw is categorized as easily exploitable by an unauthenticated attacker who has local logon access to the infrastructure where the software executes. Successful exploitation results in the unauthorized ability to cause a hang or a frequently repeatable crash of the service. The vulnerability is tracked as CVE-2026-61147 and has a CVSS 3.1 base score of 6.2, primarily impacting system availability.

Affected products

  • Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via July 2026 CPU
  • 2026-07-21: advisory: NVD publication date

References

Related threats