Executive brief
Oracle Commerce Guided Search and Experience Manager are e-commerce platforms used to deliver search and shopping experiences to customers. An unauthenticated remote vulnerability allows attackers to gain complete control over the system via the HTTP interface, potentially enabling theft of customer data, manipulation of product catalogs, or complete service disruption.
Technical details
The vulnerability is a difficult-to-exploit flaw in the Forge component of Oracle Commerce Guided Search / Experience Manager that permits unauthenticated, network-accessible remote code execution. An attacker requires no authentication credentials or user interaction to exploit this issue over HTTP. Successful exploitation results in complete system compromise, allowing an attacker to achieve confidentiality, integrity, and availability impacts. The vulnerability affects version 11.4.0; patch status from Oracle is currently unavailable in public sources.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed