Executive brief
Oracle Commerce Guided Search and Experience Manager is an e-commerce search and merchandising platform used by online retailers. An unauthenticated attacker can exploit a vulnerability in the Forge component over the network to achieve complete takeover of the system, compromising customer data, product catalogs, and transaction processing.
Technical details
This is a difficult-to-exploit remote code execution vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker with network access via HTTP can exploit this flaw without user interaction. The vulnerability allows an attacker to compromise the affected system, resulting in complete takeover with impacts to confidentiality, integrity, and availability. The affected version is 11.4.0, and patches should be available from Oracle.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed