Executive brief
A vulnerability in Oracle Commerce Experience Manager allows an attacker to take full control of the system. This software is used by businesses to manage search and customer experiences on e-commerce platforms. A successful exploit could lead to the theft of sensitive data, unauthorized modification of site content, or a complete shutdown of the commerce service.
Technical details
A vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not provided in the advisory, the CVSS vector indicates high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H) without requiring user interaction. This suggests a significant flaw in authorization or input validation within the Experience Manager component. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Commerce Guided Search / Experience Manager 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published