Executive brief
A critical vulnerability has been identified in Oracle Commerce Guided Search Platform Services, a tool used by businesses to manage and process e-commerce search data. An attacker can remotely exploit this flaw over the internet without needing any login credentials. A successful attack could lead to a complete takeover of the service, potentially allowing unauthorized access to sensitive data or disruption of the online shopping experience.
Technical details
A vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services (version 11.4.0) allows for a complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. It carries a CVSS 3.1 base score of 9.8, indicating high impacts on confidentiality, integrity, and availability. The attack vector is remote and requires no user interaction or special privileges. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Commerce Guided Search Platform Services 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory