Executive brief
Oracle Commerce Experience Manager is a component used to manage e-commerce search and product experience features. An unauthenticated attacker can exploit this vulnerability via a network-accessible HTTP endpoint to read, modify, or delete sensitive customer and business data without authorization. The vulnerability poses a critical risk to data confidentiality and integrity for organizations using affected versions.
Technical details
This is an easily exploitable unauthenticated authentication bypass or authorization flaw in Oracle Commerce Experience Manager (component of Oracle Commerce Guided Search). The vulnerability allows an attacker with network access to send HTTP requests that bypass authentication controls (PR:N indicates no privileges required). Successful exploitation results in unauthorized read and write access to critical data and all accessible product/customer information within the system. The vulnerability affects version 11.4.0; fixes or patches may be available from Oracle.
Affected products
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed