Junglewise Threat Intelligence

CVE-2026-71001: Oracle Commerce Guided Search unauthorized data access

CVE-2026-71001 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used to deliver personalized product search and shopping experiences. A vulnerability in Experience Manager allows low-privileged users to bypass access controls and read sensitive business or customer data stored in the commerce platform. An authenticated attacker with network access could exfiltrate complete datasets of product information, pricing, customer records, or other critical commerce data.

Technical details

This is an authorization bypass or information disclosure vulnerability in Oracle Commerce Experience Manager (version 11.4.0) that allows a low-privileged authenticated attacker with network access via HTTP to access unauthorized data. The vulnerability does not require user interaction and has a low complexity exploitation path. An attacker can achieve complete read access to all data accessible by the affected component, compromising confidentiality. No integrity or availability impact is documented. The vulnerability is easily exploitable and affects supported versions; patches are expected from Oracle.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats