Junglewise Threat Intelligence

CVE-2026-61163: Oracle Commerce Guided Search takeover via Forge component

CVE-2026-61163 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A high-severity vulnerability has been identified in Oracle Commerce Guided Search and Experience Manager, specifically within the Forge component. This software is used by businesses to manage product search and customer experiences on e-commerce platforms. An attacker could exploit this flaw to gain full control over the system, potentially leading to the theft of sensitive data or a complete shutdown of the online shopping experience.

Technical details

A vulnerability exists in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application. While the attack complexity is rated as high, a successful exploit results in a complete takeover of the affected product, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats