Executive brief
Oracle Commerce Guided Search and Experience Manager are components used to search and browse product catalogs in e-commerce platforms. An unauthenticated attacker can exploit a network-accessible vulnerability to gain unauthorized access to sensitive product data and catalog information, as well as temporarily disrupt search functionality. This could expose confidential business data and impact customer shopping experience.
Technical details
The vulnerability is in the Forge component of Oracle Commerce Guided Search / Experience Manager (version 11.4.0). It is an easily exploitable information disclosure and denial of service flaw requiring no authentication or user interaction, accessible over HTTP via the network. An unauthenticated attacker can retrieve critical data accessible through the application and cause partial service unavailability. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L) indicates network attack vector, no access control required, high confidentiality impact, and low availability impact. Patch status and technical details are not publicly disclosed in the available advisory text.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed