Sceawere
Vulnerability Detail
CVE-2026-61153Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Unauthorized Data Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-07-21T22:18:46.760Z",
"pubdate": "2026-07-21T22:18:46.760Z",
"executiveSummary": "This vulnerability affects Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0. It is a critical security flaw that allows an unauthenticated, remote attacker to gain unauthorized access to or modify sensitive data within the platform.\nThe vulnerability is characterized by a high severity CVSS 3.1 base score of 9.1, driven by severe impacts to both confidentiality and integrity. Because the vulnerability is easily exploitable over a network via HTTP without the requirement for user interaction or prior authentication, it poses a significant risk to the platform's data security.\nSuccessful exploitation allows an attacker to bypass standard access controls, enabling them to create, delete, or modify critical data objects within the Experience Manager component. This level of compromise can lead to complete loss of data integrity and unauthorized disclosure of sensitive information, potentially disrupting business operations or exposing proprietary commerce intelligence.",
"technicalDetails": "The vulnerability resides within the Experience Manager component of the Oracle Commerce Guided Search suite. The flaw allows for the circumvention of established authentication mechanisms, granting an unauthenticated attacker the ability to interact with internal API endpoints or backend management functions over the HTTP protocol.\nThe attack flow initiates when an unauthenticated actor submits specifically crafted HTTP requests to the target Oracle Commerce environment. Because the Experience Manager component lacks robust identity verification or authorization checks at the entry point for these requests, the application processes the instructions as if they originated from an authorized administrative session.\nThe root cause is an improper authorization implementation that fails to validate the session state or privilege level before executing critical data operations. An attacker can leverage this by identifying and invoking administrative function endpoints responsible for data management. Once access is established, the payload allows the attacker to execute CRUD (Create, Read, Update, Delete) operations on the underlying data structures accessed by the Experience Manager.\nRegarding exploitation, the low complexity requirement (AC:L) suggests that the vulnerability does not require highly specialized conditions or non-standard configurations to trigger. An attacker only requires network access to the target system. The exploit does not rely on user interaction (UI:N), meaning the compromise can be executed silently in the background.\nThe post-exploitation impact is severe, encompassing both Confidentiality (C:H) and Integrity (I:H). By manipulating the Experience Manager, an attacker can modify product catalogs, search configurations, or site metadata. Furthermore, they can exfiltrate sensitive data managed by the platform, essentially resulting in a total compromise of the application's data management plane. This vulnerability does not impact Availability (A:N), as the scope of the flaw is limited to data and object manipulation rather than service disruption or denial of service.\nThe vulnerability is limited to version 11.4.0, indicating a flaw in the product architecture that is exposed in this specific release. Because the exploit occurs over HTTP and bypasses authentication, any network-exposed instance of Oracle Commerce 11.4.0 remains highly susceptible to remote command injection and unauthorized data handling."
}