Junglewise Threat Intelligence

CVE-2026-71009: Oracle Commerce Guided Search data access vulnerability

CVE-2026-71009 · Severity: high · CVSS 7.4 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used to power product search and merchandising on retail websites. An unauthenticated attacker with network access can exploit a difficult-to-exploit vulnerability to gain unauthorized access to, modify, or delete critical customer and business data. This could result in data breaches, data loss, and service disruption affecting customer trust and business operations.

Technical details

The vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) and is exploitable by an unauthenticated attacker over HTTP without user interaction. The vulnerability allows remote attackers to bypass authentication controls and gain unauthorized access to read, create, modify, or delete critical data within the platform. Attack complexity is rated as high, suggesting specific conditions or knowledge are required. The vulnerability impacts both confidentiality (unauthorized data access) and integrity (unauthorized data modification/deletion) but not availability. No patch or detailed technical remediation information is currently available in the advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats