Junglewise Threat Intelligence

CVE-2026-71019: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71019 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are tools used to manage product search and customer experience features in e-commerce platforms. An unauthenticated attacker can exploit a vulnerability requiring user interaction to read, modify, or delete data within the product. While the vulnerability is in these search/experience components, successful exploitation could impact other parts of the Oracle Commerce platform.

Technical details

The vulnerability is an easily exploitable issue in the internal operations component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It requires network access via HTTP and user interaction from a person other than the attacker (indicating likely cross-site request forgery or similar attack). No authentication is required from the attacker. Successful exploitation allows unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The scope is changed, meaning the vulnerability may impact other products in the Oracle Commerce suite. Patch status is not confirmed from available sources.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats