Executive brief
Oracle Commerce Guided Search and Oracle Commerce Experience Manager are components used by e-commerce platforms to deliver personalized shopping experiences and search functionality. An unauthenticated attacker can exploit a vulnerability in the Forge component to achieve complete takeover of the system, potentially exposing customer data, product catalogs, and order information, and disrupting online commerce operations.
Technical details
This is a difficult-to-exploit remote code execution vulnerability affecting Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability exists in the Forge component and can be triggered by an unauthenticated attacker with network access via TCP, requiring no user interaction. Successful exploitation results in complete compromise of the affected system with high impacts to confidentiality, integrity, and availability. Patches are expected from Oracle through their Critical Patch Updates.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed