Sceawere

Vulnerability Detail

CVE-2026-61145Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce CAS Remote Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:45.880Z",
  "pubdate": "2026-07-21T22:18:45.880Z",
  "executiveSummary": "This vulnerability affects the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.\nThe flaw allows an unauthenticated, remote attacker to gain full control over the affected system via the HTTP protocol.\nClassified with a CVSS 3.1 Base Score of 9.8, the vulnerability carries a critical risk rating as it enables an attacker to achieve complete compromise of system Confidentiality, Integrity, and Availability.\nThe exploitation is characterized as 'Easily exploitable,' requiring no specialized authentication or user interaction. Successful exploitation permits an unauthorized party to execute arbitrary operations within the environment, potentially leading to unauthorized data access, modification, or total denial of service.\nOrganizations deploying Oracle Commerce Guided Search 11.4.0 face a significant security exposure, necessitating immediate attention to patching or remediation protocols to prevent potential exploitation by malicious actors possessing network access to the target instance.",
  "technicalDetails": "The vulnerability resides within the Content Acquisition System (CAS) of the Oracle Commerce Guided Search / Oracle Commerce Experience Manager suite, version 11.4.0. The architecture of the CAS component is susceptible to unauthorized manipulation due to a deficiency in secure input validation or access control enforcement within its HTTP-based interface.\nBecause the attack vector is network-based (AV:N) and requires no authentication (PR:N) or user interaction (UI:N), it is categorized as highly accessible to external threats. The attack flow initiates with an attacker crafting specifically formatted HTTP requests directed at the vulnerable CAS component.\nOnce the malicious request is transmitted, the system fails to adequately sanitize the input or restrict the execution context, allowing the attacker to bypass standard security boundaries. This manipulation likely exploits insecure deserialization, command injection, or improper resource management within the CAS processing logic.\nThe technical impact of this vulnerability is total system compromise. By leveraging this flaw, an adversary can achieve the same level of access as a legitimate system administrator. This includes the ability to retrieve sensitive data from the underlying repository (C), modify configurations or application state (I), and render the service unavailable (A).\nPost-exploitation behavior involves the attacker establishing persistence or executing further commands to manipulate the broader Oracle Commerce environment. Given that the CAS is designed to ingest data from diverse sources, the exploitation of this component may also serve as a pivot point for lateral movement within the network. The lack of defensive gating mechanisms in the CAS API at this version level means that the service directly exposes functionality that should otherwise be isolated behind robust authentication and authorization layers.\nThe susceptibility is inherent to the 11.4.0 version of the software, and the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that the vulnerability is trivial to trigger for an actor with basic network reachability, requiring no complex technical prerequisite or high-level privilege access to initiate the primary compromise."
}
CVE-2026-61145: Oracle Commerce CAS Remote Compromise (CRITICAL Severity, CVSS: 9.8) - Sceawere