Executive brief
A critical vulnerability exists in Oracle Commerce Guided Search Platform Services, a tool used by businesses to manage and process product search data. An unauthenticated attacker can exploit this flaw over the network to gain full access to sensitive data or modify critical information. This could lead to a complete compromise of the search platform's data integrity and confidentiality, potentially impacting customer-facing search results and internal business operations.
Technical details
A vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services (version 11.4.0) allows for a complete compromise of confidentiality and integrity. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. While the specific CWE is not detailed in the advisory, the impact includes unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the service. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting high impact on confidentiality and integrity without affecting availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Commerce Guided Search Platform Services 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory