Sceawere

Vulnerability Detail

CVE-2026-70978UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:17:56.587Z",
  "pubdate": "2026-08-18T21:17:56.587Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Content Acquisition System component. The affected supported version is 11.4.0. This security flaw allows unauthenticated attackers with network access via HTTP to compromise the targeted system without requiring user interaction.\nSuccessful exploitation of this vulnerability results in severe impacts on data confidentiality and integrity. An unauthorized remote attacker can gain complete access to all accessible data within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment, as well as obtain unauthorized capabilities to create, delete, or modify critical data. The CVSS 3.1 base score is 9.1, reflecting high severity due to the potential for widespread data compromise and manipulation.\nThe risk implications are critical for organizations utilizing the vulnerable version, as malicious actors can leverage this flaw over the network to compromise sensitive business data and application integrity. Due to the lack of authentication and low attack complexity requirements, immediate defensive prioritization and remediation actions are strongly recommended to prevent unauthorized data exposure and tampering.",
  "technicalDetails": "The vulnerability resides within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It exposes exposed interfaces or processing handlers over the HTTP protocol that fail to adequately validate user identity or enforce access controls prior to executing sensitive data operations.\nThe attack vector is network-based (AV:N), meaning an attacker does not require physical access or prior local presence within the target network infrastructure. The attack complexity is rated as low (AC:L), indicating that the targeted endpoints lack robust defensive mechanisms against automated probing or exploitation scripts. Furthermore, the vulnerability requires zero privileges (PR:N) and no user interaction (UI:N), allowing arbitrary actors on the network to directly target the exposed HTTP services.\nThe attack flow proceeds as follows: An unauthenticated malicious actor crafts an HTTP request targeting the vulnerable Content Acquisition System component. Because the application lacks proper authentication checks and authorization enforcement, the request is processed directly by the underlying component. Upon successful processing, the attacker bypasses security boundaries to interact with critical data.\nPost-exploitation impacts are characterized by severe breaches in confidentiality (C:H) and integrity (I:H). Attackers can read, exfiltrate, and harvest sensitive enterprise data accessible to Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Additionally, attackers can execute unauthorized create, delete, and modify operations against critical data stores, leading to potential data corruption, unauthorized insertion of malicious content, or destruction of operational records. Availability impact remains none (A:N), as the primary vector targets data exposure and modification rather than systemic denial of service."
}
CVE-2026-70978: Oracle Commerce Guided Search Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere