Junglewise Threat Intelligence

CVE-2026-71005: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71005 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager is a platform used to manage e-commerce product search and customer experience. An unauthenticated attacker can exploit this vulnerability via a malicious web page to trick logged-in users into making unauthorized changes to product data or accessing sensitive information. The attack requires user interaction but can impact customer-facing product catalogs and data integrity.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in Oracle Commerce Guided Search / Experience Manager 11.4.0. The vulnerability allows an unauthenticated attacker with network access to craft a malicious HTTP request that, when visited by an authenticated user, can modify or delete product data or read sensitive information. The attack vector is network-based and requires user interaction (the victim must visit an attacker-controlled page while logged into the Commerce system). While the vulnerability resides in the Commerce product itself, successful exploitation can impact the confidentiality and integrity of data across additional systems. The vulnerability is easily exploitable with low attack complexity and no privilege requirements.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats