Executive brief
Oracle Commerce Guided Search and Oracle Commerce Experience Manager, which power online shopping experiences, contain an access control vulnerability in their Forge component that allows low-privileged attackers to access sensitive customer and product data. An attacker can view critical business data or disrupt service availability, potentially exposing customer information and impacting e-commerce operations.
Technical details
The vulnerability is an access control weakness in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It requires low privilege access and network reachability via HTTP, with no user interaction needed. An unauthenticated or low-privileged attacker can exploit this to read unauthorized data or cause partial denial of service. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L) indicates the attack requires low privileges and network access but is otherwise straightforward to execute. Patch availability was not disclosed in the advisory reference materials.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed: Public disclosure via Oracle security alert and NVD