Junglewise Threat Intelligence

CVE-2026-71022: Oracle Commerce Guided Search and Experience Manager cross-site request forgery in Workbench

CVE-2026-71022 · Severity: high · CVSS 7.6 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Oracle Commerce Experience Manager are components used to manage product search and customer experience for e-commerce platforms. A cross-site request forgery vulnerability in the Workbench administrative interface allows attackers to trick authorized administrators into performing unauthorized actions, potentially exposing sensitive product data or modifying critical commerce configurations. This could result in data breaches, unauthorized catalog changes, or disrupted customer experience.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in the Oracle Commerce Guided Search / Experience Manager Workbench component (version 11.4.0). The vulnerability is network-accessible via HTTP and requires low-level privilege (authenticated user) combined with social engineering to trick a higher-privileged administrator into clicking a malicious link or visiting a compromised page. Successful exploitation allows an attacker to read, modify, insert, or delete sensitive data accessible through the Workbench interface with the privileges of the targeted user. The attack has scope change implications, meaning the compromise can extend beyond the affected product to other connected systems. Patch availability is unknown from the advisory content provided.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats