Executive brief
Oracle Commerce Experience Manager, a tool used by businesses to manage and deliver personalized digital shopping experiences, contains a security vulnerability. An unauthorized person can access the system over the internet without needing a username or password. If exploited, this could allow an attacker to view or steal sensitive business data and customer information stored within the platform.
Technical details
A vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (specifically version 11.4.0) allows for unauthorized data access. The flaw is categorized as easily exploitable, requiring no authentication or user interaction. An attacker can exploit this over the network via HTTP to gain unauthorized access to critical data or complete access to all data accessible by the Experience Manager component. The impact is limited to confidentiality, with no reported impact on system integrity or availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.