Executive brief
Oracle Commerce Guided Search and Oracle Commerce Experience Manager are components used to manage product search and customer experience for e-commerce platforms. A cross-site request forgery vulnerability in the Workbench administrative interface allows attackers to trick authorized administrators into performing unauthorized actions, potentially exposing sensitive product data or modifying critical commerce configurations. This could result in data breaches, unauthorized catalog changes, or disrupted customer experience.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in the Oracle Commerce Guided Search / Experience Manager Workbench component (version 11.4.0). The vulnerability is network-accessible via HTTP and requires low-level privilege (authenticated user) combined with social engineering to trick a higher-privileged administrator into clicking a malicious link or visiting a compromised page. Successful exploitation allows an attacker to read, modify, insert, or delete sensitive data accessible through the Workbench interface with the privileges of the targeted user. The attack has scope change implications, meaning the compromise can extend beyond the affected product to other connected systems. Patch availability is unknown from the advisory content provided.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed