Executive brief
Oracle Commerce Guided Search / Experience Manager is a search and content management platform used to power e-commerce storefronts. An authenticated attacker with local access to the infrastructure can exploit this vulnerability through user interaction to gain complete control of the system, compromising customer data, product catalogs, and transaction integrity.
Technical details
This privilege escalation vulnerability affects Oracle Commerce Guided Search / Experience Manager 11.4.0 and requires an attacker to have local access to the infrastructure combined with social engineering or user interaction to trigger exploitation. The vulnerability allows an unauthenticated or low-privileged user with logon capabilities to execute code with elevated privileges, resulting in complete system takeover. Attack vector is local, does not require network access, but depends on human interaction from another user. The vulnerability impacts confidentiality, integrity, and availability of the affected system.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed