Executive brief
Oracle Commerce Guided Search and Experience Manager are components that help customers search and browse products in online stores. An unauthenticated attacker can exploit this vulnerability through a network connection to take complete control of these systems, though the attack requires tricking a legitimate user into performing a specific action. A successful exploit would allow an attacker to read sensitive data, modify store operations, or disrupt customer access.
Technical details
This vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows unauthenticated remote code execution via HTTP. The attack is difficult to exploit and requires user interaction (social engineering or phishing), but once triggered can result in full system compromise affecting confidentiality, integrity, and availability. The vulnerability affects version 11.4.0; patch availability and the specific attack vector details are not fully disclosed in the advisory. Mitigation should prioritize applying available security patches and restricting network access to these systems.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed: Advisory published by Oracle