Executive brief
Oracle Commerce Guided Search and Experience Manager are search and content management components used in e-commerce platforms. This vulnerability allows unauthenticated attackers to access sensitive customer and business data, modify or delete records, and cause service disruptions—threatening the confidentiality and integrity of critical commerce operations without requiring valid credentials.
Technical details
This is an authentication bypass or input validation vulnerability in the Oracle Commerce Guided Search / Experience Manager Forge component affecting version 11.4.0. An unauthenticated attacker can exploit the flaw remotely over HTTP without user interaction, despite difficult exploit conditions (indicated by CVSS Attack Complexity: High). Successful exploitation allows unauthorized read access to all accessible data, selective write/delete access to some data, and ability to cause partial denial of service. No public exploit code is currently known to be circulating in the wild.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed