Executive brief
Oracle Commerce Guided Search / Experience Manager is a search and merchandising component used in e-commerce storefronts. An unauthenticated attacker can exploit this vulnerability over the network to gain unauthorized access to sensitive customer data, product catalogs, and other critical business information without requiring any authentication or user interaction.
Technical details
This is an authentication bypass vulnerability in Oracle Commerce Guided Search / Experience Manager (version 11.4.0). The vulnerability allows an unauthenticated attacker with network access via HTTP to access confidential data without credentials. The attack has a low complexity and does not require user interaction. An attacker can retrieve all data accessible through the affected component, resulting in complete disclosure of stored information. Oracle has classified this as a network-reachable, easily exploitable vulnerability with high confidentiality impact.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed