Executive brief
Oracle Commerce Guided Search and Experience Manager are search and content management components used in e-commerce and digital storefront platforms. This vulnerability allows attackers to crash the service and read sensitive data without authentication, disrupting customer shopping experiences and potentially exposing product catalogs or configuration information.
Technical details
This is an easily exploitable vulnerability in Oracle Commerce Guided Search and Experience Manager's Forge component affecting version 11.4.0. The vulnerability can be triggered remotely via HTTP by unauthenticated attackers without additional privileges or user interaction. Exploitation results in a denial of service (hang or crash of the affected service) and unauthorized read access to a subset of accessible application data. The component likely contains a flaw such as improper input validation, resource exhaustion, or information disclosure in its HTTP request handling. No patch details are currently available in the provided advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed