Executive brief
A vulnerability exists in Oracle Commerce Experience Manager, a platform used by businesses to manage and deliver personalized digital shopping experiences. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft of critical information or the unauthorized modification and deletion of data within the commerce system.
Technical details
This vulnerability affects the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized read access to all accessible data (high confidentiality impact) and unauthorized update, insert, or delete access to a subset of data (low integrity impact). The vulnerability does not appear to impact system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory