Sceawere

Vulnerability Detail

CVE-2026-70982UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-18T21:17:57.050Z",
  "pubdate": "2026-08-18T21:17:57.050Z",
  "executiveSummary": "An unauthenticated information disclosure vulnerability affects the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This flaw allows remote attackers with network access via HTTP to bypass security controls and compromise the application due to its difficulty of exploitation requiring high attack complexity.\nSuccessful exploitation of this vulnerability results in unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Due to a scope change, attacks against this specific component can significantly impact additional integrated products within the enterprise architecture.\nThe vulnerability carries a CVSS 3.1 Base Score of 6.8, with impacts exclusively affecting confidentiality (C:H, I:N, A:N). Attackers require no privileges and no user interaction, relying solely on network connectivity over HTTP to target the vulnerable application layer.",
  "technicalDetails": "The vulnerability resides within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from improper access control enforcement or insufficient input validation handling within the HTTP request processing pipeline, allowing unauthorized retrieval of sensitive data repositories.\nExploitation is classified as having high attack complexity (AC:H), indicating that successful compromise requires specific preconditions, precise timing, or non-default configurations by the attacker to bypass existing security mechanisms.\nThe attack vector is network-based (AV:N), allowing any unauthenticated remote adversary (PR:N) with HTTP connectivity to initiate malicious requests against the target server without requiring user interaction (UI:N).\nThe attack flow begins with the adversary crafting specific HTTP requests directed at the exposed Content Acquisition System endpoints. Because of the scope change (S:C) characteristic of this vulnerability, the successful execution of the request transcends the immediate boundaries of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, potentially exposing interconnected systems or collateral data stores.\nUpon successful processing of the crafted payload by the vulnerable component, the application leaks critical proprietary information or grants unauthorized read access to all data accessible within the context of the service, leading to a complete compromise of confidentiality."
}
CVE-2026-70982: Oracle Commerce Guided Search Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 6.8) - Sceawere