Junglewise Threat Intelligence

CVE-2026-61149: Oracle Commerce Experience Manager account takeover vulnerability

CVE-2026-61149 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager, a tool used by businesses to manage and personalize customer search and shopping experiences, contains a security vulnerability. An attacker with basic user access to the network can exploit this flaw to take full control of the system. This could lead to the theft of sensitive customer data, disruption of the online storefront, or unauthorized changes to the shopping experience.

Technical details

A vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows for a complete system compromise. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific vulnerability class (e.g., injection, broken access control) is not explicitly named in the advisory, the impact is rated for high Confidentiality, Integrity, and Availability loss, resulting in a full takeover. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.

References

Related threats