Junglewise Threat Intelligence

CVE-2026-71035: Oracle Commerce Guided Search remote takeover in Forge

CVE-2026-71035 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components that help online retailers organize and present product catalogs to customers. An unauthenticated attacker can remotely exploit a difficult-to-exploit vulnerability in the Forge component to gain complete control over the system, compromising customer data, product information, and service availability.

Technical details

This is a difficult-to-exploit vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) that allows unauthenticated attackers with network access to achieve complete system compromise. The vulnerability is reachable via HTTP and requires no user interaction, though exploitation difficulty is high (AC:H in the CVSS vector). Successful exploitation results in full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability affects Oracle Commerce version 11.4.0, and patches should be available through Oracle's standard security advisory channels.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats