Junglewise Threat Intelligence

CVE-2026-61150: Oracle Commerce Experience Manager data compromise via HTTP

CVE-2026-61150 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Commerce Experience Manager, a platform used by businesses to manage and deliver personalized digital shopping experiences. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, deletion, or modification of critical commerce information, potentially disrupting operations and compromising customer or product data.

Technical details

This vulnerability affects the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The vulnerability allows an attacker to bypass intended access controls to achieve unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the component. The CVSS 3.1 score of 8.1 reflects high impacts on confidentiality and integrity, though availability is not directly impacted. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update

References

Related threats