Executive brief
Oracle Commerce Guided Search and Experience Manager are components that handle product search and shopping experiences in e-commerce platforms. A vulnerability in the Forge component allows an attacker with local access to the infrastructure to execute arbitrary code and completely compromise the system, affecting the confidentiality, integrity, and availability of the e-commerce platform and customer data.
Technical details
This is a local privilege escalation or code execution vulnerability in the Forge component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. The vulnerability is easily exploitable from the local system (AV:L) with no privileges required (PR:N), but requires user interaction (UI:R) for successful exploitation. An unauthenticated attacker with logon access to the infrastructure can exploit this to achieve complete system compromise with high impact on confidentiality, integrity, and availability. No patch information is currently available from the advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed