Executive brief
A security vulnerability has been identified in Oracle Commerce Guided Search and Experience Manager, specifically within the Content Acquisition System component. This software is used by businesses to manage product search and customer experiences on e-commerce platforms. If exploited, an attacker could gain unauthorized access to sensitive data or modify critical information, potentially leading to data theft or disruption of the online shopping experience.
Technical details
This vulnerability affects the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is classified as a high-severity issue that allows an unauthenticated attacker with network access via HTTPS to compromise the system. The attack complexity is rated as high, suggesting that successful exploitation may require specific environmental conditions or specialized knowledge. If successful, the attacker can achieve unauthorized creation, deletion, or modification of all accessible data, as well as full read access to critical information. The vulnerability impacts confidentiality and integrity but does not directly impact service availability.
Affected products
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 CPU
- 2026-07-21: disclosed: CVE published to NVD dataset