Executive brief
Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used to power product search and shopping experiences. A low-privileged user with local access to the server can exploit this vulnerability to modify or delete critical business data or cause complete service outages, impacting customer transactions and platform availability.
Technical details
This is a local privilege escalation vulnerability in the Forge component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability requires low privilege logon access to the infrastructure where the application runs and does not require user interaction. A successful exploit allows an attacker to gain unauthorized modification or deletion of critical data and the ability to cause denial of service through process hangs or crashes. Patch status was not explicitly confirmed in the advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed