Executive brief
Oracle Commerce Guided Search and Experience Manager are components that help online retailers organize and present product catalogs to customers. An unauthenticated attacker can remotely exploit a difficult-to-exploit vulnerability in the Forge component to gain complete control over the system, compromising customer data, product information, and service availability.
Technical details
This is a difficult-to-exploit vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) that allows unauthenticated attackers with network access to achieve complete system compromise. The vulnerability is reachable via HTTP and requires no user interaction, though exploitation difficulty is high (AC:H in the CVSS vector). Successful exploitation results in full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability affects Oracle Commerce version 11.4.0, and patches should be available through Oracle's standard security advisory channels.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed