Sceawere
Vulnerability Detail
CVE-2026-70980UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search Takeover Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-08-18T21:17:56.820Z",
"pubdate": "2026-08-18T21:17:56.820Z",
"executiveSummary": "A critical security vulnerability exists within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically affecting the Content Acquisition System component in version 11.4.0. This remote vulnerability allows an unauthenticated adversary with network access via HTTP to execute sophisticated attacks resulting in the complete takeover of the affected product. The severity of the issue is underscored by a CVSS 3.1 Base Score of 9.0, reflecting maximum potential impacts across confidentiality, integrity, and availability. Furthermore, the vulnerability exhibits a scope change (S:C), indicating that successful exploitation may significantly impact additional integrated products within the ecosystem. Although the attack complexity is characterized as high, the lack of authentication and privilege requirements significantly lowers the barrier to entry for external threat actors targeting exposed network services. Organizations utilizing the supported version 11.4.0 face severe risk exposure, necessitating immediate remediation action to prevent unauthorized system compromise and potential lateral movement across dependent architectures.",
"technicalDetails": "The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The architecture of this component exposes network-accessible interfaces over the HTTP protocol, which can be leveraged by unauthenticated remote attackers to interact with vulnerable backend functions. Although the exploitation requires high attack complexity (AC:H), successful execution bypasses all security controls due to the absence of required privileges (PR:N) and user interaction (UI:N). The attack flow commences when an unauthenticated threat actor leverages network access to transmit maliciously crafted HTTP payloads directly to the exposed Content Acquisition System endpoints. The root cause stems from improper input validation, insecure deserialization, or flawed state handling within the affected component, allowing specially formatted requests to manipulate internal application logic. As the payload is processed by the vulnerable component, it triggers memory corruption, arbitrary code execution, or privilege escalation paths. Because the vulnerability exhibits a scope change (S:C), the compromise is not strictly confined to the boundary of the Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance; rather, successful exploitation enables the attacker to leverage the initial foothold to impact additional, interconnected enterprise products. The post-exploitation phase results in a full system takeover, granting the adversary high-level administrative control over confidentiality, integrity, and availability (C:H/I:H/A:H). This grants the attacker the capability to exfiltrate sensitive commercial data, modify critical product catalogs or search indices, disrupt business-critical operations, and potentially pivot to adjacent systems residing within the same network segment."
}