Executive brief
Oracle Commerce Guided Search and Experience Manager are tools used to manage product search and customer experience features in e-commerce platforms. An unauthenticated attacker can exploit a vulnerability requiring user interaction to read, modify, or delete data within the product. While the vulnerability is in these search/experience components, successful exploitation could impact other parts of the Oracle Commerce platform.
Technical details
The vulnerability is an easily exploitable issue in the internal operations component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It requires network access via HTTP and user interaction from a person other than the attacker (indicating likely cross-site request forgery or similar attack). No authentication is required from the attacker. Successful exploitation allows unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The scope is changed, meaning the vulnerability may impact other products in the Oracle Commerce suite. Patch status is not confirmed from available sources.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed