Junglewise Threat Intelligence

CVE-2026-71037: Oracle Commerce Guided Search remote code execution via HTTP

CVE-2026-71037 · Severity: critical · CVSS 9.3 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search is a search and product discovery component used in e-commerce platforms to help customers find products. An unauthenticated attacker with network access can exploit this vulnerability via HTTP to modify, delete, or access sensitive customer data and product information in the commerce system, potentially affecting the entire e-commerce platform and customer trust.

Technical details

A cross-site request forgery or similar attack vector vulnerability exists in Oracle Commerce Guided Search / Experience Manager (version 11.4.0) that allows unauthenticated network access via HTTP. The vulnerability is classified with high confidentiality and integrity impacts (CVSS 3.1: 9.3, AV:N/AC:L/PR:N). User interaction is required, likely through social engineering or malicious link. Successful exploitation results in unauthorized creation, deletion, or modification of critical data accessible to the application, with scope change indicating potential impact to connected systems. No patch information is currently available in the advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats