Junglewise Threat Intelligence

CVE-2026-71004: Oracle Commerce Experience Manager CSRF in guided search

CVE-2026-71004 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager is a component used to manage search and product discovery for e-commerce platforms. An unauthenticated attacker can trick a user into modifying or deleting product data through a cross-site request forgery (CSRF) attack, resulting in unauthorized changes to catalog information and potential data exposure. Exploitation requires user interaction but can affect both the targeted system and connected products.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in Oracle Commerce Experience Manager (component: Guided Search), affecting version 11.4.0. The vulnerability is easily exploitable by an unauthenticated attacker via HTTP, requiring user interaction (UI:R) but no prior authentication (PR:N). The attack vector is network-based, and successful exploitation allows unauthorized read, update, insert, and delete access to data accessible by the Experience Manager. The scope is changed, indicating that a vulnerability in one product can impact additional Oracle Commerce products. Patches or mitigations should be available through Oracle security updates.

Affected products

  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats