Executive brief
A vulnerability exists in Oracle Commerce Experience Manager, a platform used by businesses to manage and deliver personalized digital shopping experiences. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, deletion, or modification of critical commerce information, potentially disrupting operations and compromising customer or product data.
Technical details
This vulnerability affects the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The vulnerability allows an attacker to bypass intended access controls to achieve unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the component. The CVSS 3.1 score of 8.1 reflects high impacts on confidentiality and integrity, though availability is not directly impacted. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: advisory: Published as part of Oracle Critical Patch Update