Junglewise Threat Intelligence

CVE-2026-61153: Oracle Commerce Experience Manager unauthorized data access

CVE-2026-61153 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Commerce Experience Manager, a platform used by businesses to manage and deliver personalized digital shopping experiences. An unauthenticated attacker can exploit this flaw over the network to gain full access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical customer and operational information, potentially leading to significant data breaches or business disruption.

Technical details

This vulnerability affects the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is classified as an unauthenticated remote exploit reachable via HTTP. The flaw allows an attacker to bypass security controls to achieve unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data managed by the component. The CVSS 3.1 base score is 9.1, reflecting high confidentiality and integrity impacts with no requirement for user interaction or elevated privileges. Users are advised to consult the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Commerce Guided Search / Experience Manager 11.4.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 CPU

References

Related threats