Junglewise Threat Intelligence

CVE-2026-61148: Oracle Commerce Experience Manager takeover vulnerability

CVE-2026-61148 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A vulnerability in Oracle Commerce Experience Manager allows an attacker to take full control of the system. This software is used by businesses to manage search and customer experiences on e-commerce platforms. A successful exploit could lead to the theft of sensitive data, unauthorized modification of site content, or a complete shutdown of the commerce service.

Technical details

A vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not provided in the advisory, the CVSS vector indicates high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H) without requiring user interaction. This suggests a significant flaw in authorization or input validation within the Experience Manager component. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Commerce Guided Search / Experience Manager 11.4.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats