Executive brief
A vulnerability exists in Oracle Commerce Experience Manager, a platform used by businesses to manage and deliver personalized digital shopping experiences. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive business or customer data. This could lead to a significant breach of confidential information and impact the organization's reputation and compliance standing.
Technical details
A vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (specifically version 11.4.0) allows for unauthorized data access. The flaw is categorized as easily exploitable and does not require user interaction or administrative privileges. An attacker with network access via HTTP can exploit this vulnerability to compromise the confidentiality of the system, potentially gaining complete access to all data accessible by the Experience Manager. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: disclosed: Initial advisory publication by Oracle and NVD.