Executive brief
Oracle Commerce Guided Search is a component used in e-commerce platforms to enable search and merchandising capabilities. An unauthenticated attacker can exploit this vulnerability over the network to steal sensitive business and customer data or crash the service entirely, disrupting online sales and operations.
Technical details
This is a network-accessible vulnerability in Oracle Commerce Guided Search (Experience Manager component) affecting version 11.4.0 that requires no authentication and no user interaction. The vulnerability allows an unauthenticated attacker with HTTP network access to achieve unauthorized data access and cause denial of service through repeated crashes or hangs. The attack is easily exploitable due to low attack complexity (AC:L). While the specific vulnerability class is not detailed in the advisory, the impacts indicate both confidentiality (unauthorized access to critical data) and availability compromise (DOS).
Affected products
- Oracle Commerce Guided Search 11.4.0
Timeline
- 2026-08-18: disclosed