Junglewise Threat Intelligence

CVE-2026-71012: Oracle Commerce Guided Search authentication bypass

CVE-2026-71012 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used to power product discovery and customer experience in e-commerce platforms. A flaw in access control allows low-privilege attackers to view sensitive product data and configuration information, and disrupt search functionality for customers. This could expose confidential business data and harm the shopping experience.

Technical details

An authentication or authorization bypass vulnerability in Oracle Commerce Guided Search / Experience Manager (version 11.4.0) allows a low-privileged attacker with network access to bypass access controls via HTTP requests. The vulnerability is easily exploitable and requires no user interaction. Successful exploitation enables unauthorized access to critical data stored in the system and can cause partial denial of service. The affected component is Experience Manager within the Guided Search product.

Affected products

  • Oracle Commerce Guided Search 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats