Junglewise Threat Intelligence

CVE-2026-61164: Oracle Commerce Guided Search data compromise in Content Acquisition System

CVE-2026-61164 · Severity: high · CVSS 7.4 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A security vulnerability has been identified in Oracle Commerce Guided Search and Experience Manager, specifically within the Content Acquisition System component. This software is used by businesses to manage product search and customer experiences on e-commerce platforms. If exploited, an attacker could gain unauthorized access to sensitive data or modify critical information, potentially leading to data theft or disruption of the online shopping experience.

Technical details

This vulnerability affects the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is classified as a high-severity issue that allows an unauthenticated attacker with network access via HTTPS to compromise the system. The attack complexity is rated as high, suggesting that successful exploitation may require specific environmental conditions or specialized knowledge. If successful, the attacker can achieve unauthorized creation, deletion, or modification of all accessible data, as well as full read access to critical information. The vulnerability impacts confidentiality and integrity but does not directly impact service availability.

Affected products

  • Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 CPU
  • 2026-07-21: disclosed: CVE published to NVD dataset

References

Related threats