Junglewise Threat Intelligence

CVE-2026-71000: Oracle Commerce Experience Manager cross-site request forgery

CVE-2026-71000 · Severity: high · CVSS 8.7 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager is a component used to manage and deliver personalized shopping experiences in e-commerce systems. This vulnerability allows a low-privileged user to trick another user into performing unauthorized actions—such as creating, modifying, or deleting critical customer or business data—through a malicious web request. Successful exploitation requires user interaction and can result in unauthorized access to or modification of sensitive commerce data.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in Oracle Commerce Experience Manager (component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager). The vulnerability is easily exploitable via HTTP by a low-privileged attacker with network access and requires human interaction (social engineering). It affects confidentiality and integrity of critical data, with scope change indicating that the impact extends beyond the vulnerable component itself. The vulnerability has been assigned CVSS 3.1 score 8.7 (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Patch availability from Oracle is expected via their security alert bulletin.

Affected products

  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats