Junglewise Threat Intelligence

CVE-2026-61155: Oracle Commerce Guided Search Platform Services data exposure in Forge

CVE-2026-61155 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle Commerce Guided Search Platform Services. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Commerce Guided Search Platform Services, specifically within the Forge component. This software is used by businesses to manage and process product data for e-commerce search engines. An attacker could exploit this flaw to steal sensitive business data or crash the search service entirely, leading to significant operational downtime and loss of customer trust.

Technical details

A vulnerability exists in the Forge component of Oracle Commerce Guided Search Platform Services version 11.4.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for unauthorized access to critical data or complete access to all data accessible by the service. Additionally, the vulnerability can be leveraged to cause a hang or a frequently repeatable crash, resulting in a complete denial-of-service (DoS). The CVSS 3.1 score of 9.1 reflects high impacts on confidentiality and availability, though integrity is not directly affected. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Commerce Guided Search Platform Services 11.4.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61155 by Oracle.
  • 2026-07-21: advisory: Included in the Oracle July 2026 Critical Patch Update.

References

Related threats