Junglewise Threat Intelligence

CVE-2026-71002: Oracle Commerce Guided Search and Experience Manager unauthorized data access

CVE-2026-71002 · Severity: high · CVSS 8.5 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager is a web-based search and merchandising platform used to power e-commerce product discovery and content management. A vulnerability in version 11.4.0 allows an authenticated attacker to read sensitive data and modify or delete critical information without proper authorization, potentially compromising customer product catalogs and transaction data across connected systems.

Technical details

This is an access control vulnerability in Oracle Commerce Experience Manager (component of Oracle Commerce Guided Search / Experience Manager) that allows an attacker with low-privilege network access via HTTP to bypass authorization checks. The vulnerability requires network access and low-level authentication credentials; no user interaction is needed. A successful exploit can result in unauthorized creation, deletion, and modification of critical data, as well as read access to sensitive application data. The vulnerability has scope change implications, meaning attacks may impact other Oracle Commerce products connected to the affected system. Patches are available via Oracle's Critical Patch Update program.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed: Published in Oracle Critical Patch Update

References

Related threats