Executive brief
Oracle Commerce Guided Search and Experience Manager provide core e-commerce search and storefront management capabilities for online retailers. An unauthenticated attacker can exploit a network-accessible vulnerability to access sensitive customer and product data without authorization, and modify or delete critical business information. This could expose customer records, payment data, and enable defacement or operational disruption of the online storefront.
Technical details
An easily exploitable authentication bypass vulnerability exists in Oracle Commerce Guided Search / Experience Manager (version 11.4.0) that allows unauthenticated attackers to access the application via HTTP without valid credentials. The vulnerability resides in the Experience Manager component and requires no user interaction or special access. Successful exploitation grants unauthorized read access to all accessible data including sensitive customer information, and write access (insert, update, delete) to some data sets. The vulnerability is remotely exploitable over the network with low attack complexity.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed