Executive brief
Oracle Commerce Guided Search and Experience Manager are e-commerce platform components used to power online shopping experiences and product discovery. An unauthenticated remote vulnerability in these components allows attackers to take complete control of the system, leading to potential data theft, service disruption, and compromise of customer information stored in the commerce platform.
Technical details
This is a difficult-to-exploit unauthenticated remote code execution vulnerability in the Forge component of Oracle Commerce Guided Search/Experience Manager. The vulnerability is reachable over TCP from the network without requiring authentication or user interaction. A successful attack results in complete compromise of the affected system with high impact to confidentiality, integrity, and availability. The exact vulnerability mechanism is not detailed in available sources, though the difficulty rating suggests specific preconditions or environmental factors may limit widespread exploitation.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed