Executive brief
Oracle Commerce Experience Manager is a tool used to manage and customize e-commerce storefront experiences. An unauthenticated attacker can trick a legitimate user into unknowingly performing unauthorized operations—such as modifying or deleting product data—through a malicious web request. The vulnerability requires user interaction and can impact data integrity across connected commerce systems.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in Oracle Commerce Experience Manager (version 11.4.0) that allows an unauthenticated attacker to perform unauthorized data modifications via HTTP. The vulnerability is easily exploitable from the network and requires no authentication from the attacker, but does require user interaction (victim must click a link or visit a malicious page). Successful exploitation results in unauthorized update, insert, or delete access to accessible data, as well as unauthorized read access to a subset of data. The scope is marked as changed, indicating attacks may impact additional products beyond Experience Manager itself. A patch or update is likely available from Oracle.
Affected products
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed