Junglewise Threat Intelligence

CVE-2026-61158: Oracle Commerce Experience Manager unauthorized data access via RMI

CVE-2026-61158 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager, a platform used by businesses to manage digital search and customer experiences, contains a security vulnerability. An unauthorized person could use this flaw to gain access to sensitive business data or all information stored within the system. This could lead to the exposure of proprietary configurations or customer-facing data, potentially impacting business operations and data privacy.

Technical details

A vulnerability exists in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw is exploitable via the Remote Method Invocation (RMI) protocol by an unauthenticated attacker with network access to the service. Successful exploitation allows for unauthorized access to critical data or complete access to all data accessible by the Experience Manager. The vulnerability is characterized by a high confidentiality impact with no reported impact on integrity or availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update
  • 2026-07-21: advisory: NVD publication date

References

Related threats