Junglewise Threat Intelligence

CVE-2026-71003: Oracle Commerce Guided Search and Experience Manager information disclosure and denial of service

CVE-2026-71003 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used by e-commerce businesses to power product search and customer experience features. This vulnerability allows a low-privileged attacker with network access to steal customer data and product information, as well as temporarily disrupt the search and experience functionality for end users.

Technical details

This is an information disclosure and partial denial-of-service vulnerability in Oracle Commerce Guided Search / Experience Manager that can be exploited over HTTP by an attacker with low privileges. The vulnerability requires network access but no user interaction. A successful exploit allows unauthorized access to critical data stored in the application and the ability to cause partial unavailability of the service. The vulnerability affects Oracle Commerce version 11.4.0. Patch availability and specific technical root cause details are not currently available from the provided advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats