Junglewise Threat Intelligence

CVE-2026-71007: Oracle Commerce Experience Manager unauthorized data access

CVE-2026-71007 · Severity: medium · CVSS 6.8 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager is a component used for managing guided search and customer experience features in e-commerce platforms. A vulnerability in version 11.4.0 allows a high-privileged attacker with network access to gain unauthorized access to critical business data, potentially exposing customer information, product catalogs, and other sensitive commerce data stored within the system.

Technical details

This vulnerability in Oracle Commerce Experience Manager allows an attacker with high privileges and network access via HTTP to bypass access controls and read sensitive data. The vulnerability has a CVSS score of 6.8 and carries a scope change impact, meaning successful exploitation could affect additional products beyond the vulnerable component itself. The attack requires no user interaction and no special network conditions (low complexity). Patches or mitigations should be obtained from Oracle's security advisories.

Affected products

  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed: Published on Oracle Critical Patch Update

References

Related threats