Junglewise Threat Intelligence

CVE-2026-71024: Oracle Commerce Guided Search information disclosure and denial of service

CVE-2026-71024 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used to search and browse product catalogs in e-commerce platforms. An unauthenticated attacker can exploit a network-accessible vulnerability to gain unauthorized access to sensitive product data and catalog information, as well as temporarily disrupt search functionality. This could expose confidential business data and impact customer shopping experience.

Technical details

The vulnerability is in the Forge component of Oracle Commerce Guided Search / Experience Manager (version 11.4.0). It is an easily exploitable information disclosure and denial of service flaw requiring no authentication or user interaction, accessible over HTTP via the network. An unauthenticated attacker can retrieve critical data accessible through the application and cause partial service unavailability. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L) indicates network attack vector, no access control required, high confidentiality impact, and low availability impact. Patch status and technical details are not publicly disclosed in the available advisory text.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats