Junglewise Threat Intelligence

CVE-2026-70999: Oracle Commerce Guided Search privilege escalation in Experience Manager

CVE-2026-70999 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager components allow customers to manage e-commerce product catalogs and customer experiences. A vulnerability in these components lets a low-privileged user with network access modify or delete critical business data, including product information and customer records, potentially disrupting sales operations and customer trust.

Technical details

This is an authorization bypass vulnerability in Oracle Commerce Guided Search / Experience Manager that allows a low-privileged, authenticated attacker with network access to perform unauthorized create, delete, and modify operations on critical data. The vulnerability is reachable via HTTP and requires valid user credentials (PR:L = low privilege required). Successful exploitation results in compromise of data confidentiality and integrity (CVSS C:H/I:H). The affected version is 11.4.0. Patch availability and specific technical remediation details are not provided in the available advisory text.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats