Executive brief
Oracle Commerce Guided Search and Experience Manager, components used to manage product search and browsing experiences in e-commerce platforms, contain a vulnerability that allows unauthenticated attackers to modify or read sensitive customer and product data. An attacker can trick a legitimate user into performing unauthorized actions on the system, potentially leading to unauthorized changes in product listings, pricing, or customer information.
Technical details
The vulnerability is a cross-site request forgery (CSRF) or similar client-side attack vector affecting Oracle Commerce Guided Search / Experience Manager version 11.4.0. It is easily exploitable with no authentication required and network-accessible via HTTP, but requires user interaction (social engineering or malicious link click) to succeed. The vulnerability has a scope change, meaning attacks against this component can impact other systems in the Oracle Commerce environment. Successful exploitation allows unauthorized read and write access (update, insert, delete) to data accessible through the affected component. The CVSS 3.1 score of 6.1 reflects low confidentiality and integrity impacts with no availability impact.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed