Sceawere
Vulnerability Detail
CVE-2026-61146Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce CAS RCE Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:45.990Z",
"pubdate": "2026-07-21T22:18:45.990Z",
"executiveSummary": "This vulnerability affects the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.\nThe vulnerability is characterized as an easily exploitable flaw that permits a low-privileged attacker to achieve a full system takeover via network-based HTTP requests.\nWith a CVSS 3.1 base score of 9.9, the vulnerability poses a critical risk to confidentiality, integrity, and availability.\nA significant feature of this vulnerability is the scope change (S:C), indicating that successful exploitation may facilitate lateral movement or compromise of peripheral systems integrated with the Oracle Commerce ecosystem.\nThe attack vector is network-based (AV:N), requiring only low-privileged access (PR:L) and no user interaction (UI:N), significantly lowering the threshold for malicious actors.\nThe potential impact includes complete unauthorized control over the affected Oracle Commerce instance, necessitating immediate attention from security teams to isolate impacted environments.",
"technicalDetails": "The vulnerability exists within the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. The vulnerability allows for arbitrary command execution or similar code injection scenarios, culminating in a total compromise of the application server.\nThe attack flow initiates via an HTTP request directed at the Content Acquisition System. Given the low-privilege requirement, an attacker authenticated with basic user credentials can interact with specific API endpoints or management interfaces exposed by the CAS. By crafting malicious input, the attacker leverages the vulnerability to bypass security controls and execute arbitrary operations in the context of the service.\nThe vulnerability is classified with a scope change (S:C) metric, which is technically significant. This implies that the vulnerability allows the attacker to influence resources beyond the initial security boundaries of the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment. This is often associated with the compromise of underlying system binaries or configuration files that dictate how the Content Acquisition System interacts with external data sources, repositories, or linked infrastructure.\nThe technical impact is exhaustive, as indicated by the 'H' (High) ratings for Confidentiality, Integrity, and Availability. Upon successful injection and execution, the attacker can manipulate internal database records, exfiltrate sensitive commerce data, or disrupt business continuity by crashing the service or modifying application logic. Furthermore, because the Content Acquisition System often operates with elevated system permissions to facilitate data indexing and ingestion, the attacker can inherit these privileges, potentially facilitating persistent access to the host server.\nThe lack of user interaction requirement (UI:N) confirms that the exploitation is automated and deterministic, allowing for potential wormable behavior or rapid mass exploitation within an enterprise network. The primary root cause likely stems from improper input validation or insecure deserialization/processing of data streams handled by the CAS during the acquisition phase. Without robust sanitization of incoming requests, the component fails to neutralize malicious payloads, allowing for the escalation from a low-privileged account to full administrative control of the target platform."
}