Executive brief
Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used by online retailers to power product search and shopping experiences. An unauthenticated attacker can exploit a vulnerability in the Forge component to gain unauthorized access to sensitive customer data and product information without authentication. This could lead to exposure of confidential business data, customer details, and complete compromise of the search functionality availability.
Technical details
The vulnerability exists in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is an easily exploitable vulnerability that allows unauthenticated attackers to send malicious SOAP requests over the network to bypass access controls. The attack requires no authentication, no special configuration, and no user interaction. Successful exploitation results in unauthorized read access to critical data and complete exposure of all data accessible through the affected components. The vulnerability has a CVSS 3.1 score of 7.5 with high confidentiality impact.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed: Public disclosure via Oracle security alert