Executive brief
Oracle Commerce Experience Manager, a tool used by businesses to manage and personalize digital shopping experiences, contains a high-severity vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to access sensitive corporate data or cause the entire system to crash. This could lead to significant data exposure and prolonged downtime for the e-commerce platform.
Technical details
A vulnerability exists in the Experience Manager component of Oracle Commerce Guided Search (formerly Endeca). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized access to critical data or complete access to all data accessible by the component. Additionally, the attacker can cause a hang or a frequently repeatable crash, resulting in a complete denial-of-service (DoS). The vulnerability affects version 11.4.0 and is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Commerce Guided Search / Experience Manager 11.4.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-61160 was published to the NVD.