Executive brief
Oracle Commerce Guided Search and Experience Manager are components used to power product discovery and customer experience in e-commerce platforms. A flaw in access control allows low-privilege attackers to view sensitive product data and configuration information, and disrupt search functionality for customers. This could expose confidential business data and harm the shopping experience.
Technical details
An authentication or authorization bypass vulnerability in Oracle Commerce Guided Search / Experience Manager (version 11.4.0) allows a low-privileged attacker with network access to bypass access controls via HTTP requests. The vulnerability is easily exploitable and requires no user interaction. Successful exploitation enables unauthorized access to critical data stored in the system and can cause partial denial of service. The affected component is Experience Manager within the Guided Search product.
Affected products
- Oracle Commerce Guided Search 11.4.0
Timeline
- 2026-08-18: disclosed