Junglewise Threat Intelligence

CVE-2026-71008: Oracle Commerce Experience Manager unauthorized data access

CVE-2026-71008 · Severity: medium · CVSS 6.8 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Experience Manager is a component used to manage and deliver personalized shopping experiences in e-commerce platforms. A vulnerability allows a high-privileged attacker with network access to view sensitive customer data and product information without proper authorization. This could expose confidential business data and customer information that competitors or malicious actors could exploit.

Technical details

The vulnerability is an authorization bypass in Oracle Commerce Experience Manager (part of Oracle Commerce Guided Search) affecting version 11.4.0. It requires high-privilege credentials and network-level HTTP access but does not require user interaction. An attacker with administrative or elevated privileges can access confidential data beyond their intended scope. The vulnerability has scope change implications, potentially affecting other connected Oracle Commerce components. Patch status is not explicitly confirmed in the advisory text.

Affected products

  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats