Junglewise Threat Intelligence

CVE-2026-71038: Oracle Commerce Guided Search information disclosure

CVE-2026-71038 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager is a product used to manage and optimize online shopping experiences. An unauthenticated attacker can exploit this vulnerability via network access to gain unauthorized access to sensitive customer and commerce data without any authentication or user interaction required.

Technical details

This is a network-accessible information disclosure vulnerability in Oracle Commerce Guided Search / Experience Manager (version 11.4.0) that allows unauthenticated attackers to read critical and sensitive data. The vulnerability is exploitable via HTTP with no authentication, credentials, or special preconditions required (CVSS vector: AV:N/AC:L/PR:N/UI:N). Successful exploitation results in unauthorized access to all data accessible through the vulnerable component, with confidentiality impact but no integrity or availability impact. Patch availability has not been confirmed in the available advisory materials.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats