Sceawere
Vulnerability Detail
CVE-2026-70983UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search CAS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-08-18T21:17:57.173Z",
"pubdate": "2026-08-18T21:17:57.173Z",
"executiveSummary": "An unauthenticated, network-accessible vulnerability exists within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This security flaw is categorized as difficult to exploit but presents a significant risk due to its potential for a scope change affecting additional products. An external threat actor communicating via HTTP can leverage this vulnerability without prior authentication or user interaction. Successful exploitation leads directly to unauthorized confidentiality impacts, granting the attacker unauthorized read access to critical data or complete access to all data accessible by the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product suite. Given the severity of the data exposure and the potential cascading effects on auxiliary systems, organizations utilizing the affected version face elevated risks regarding sensitive information disclosure and regulatory compliance failures.",
"technicalDetails": "The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically affecting version 11.4.0. The attack vector is strictly network-based, utilizing the HTTP protocol to interact with the vulnerable application endpoints. The CVSS 3.1 vector is defined as CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N, indicating an Attack Vector (AV) of Network, Attack Complexity (AC) of High, Privileges Required (PR) of None, and User Interaction (UI) of None. The Scope (S) is marked as Changed, meaning a successful exploit against the primary component impacts resources beyond the security scope of the vulnerable Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance. The confidentiality impact (C) is rated as High, while integrity (I) and availability (A) impacts are None. Although the vulnerability is classified as difficult to exploit requiring specific conditions or complex request handling, an unauthenticated attacker can initiate the attack sequence over the network. The step-by-step attack flow involves crafting specialized HTTP requests targeting the vulnerable Content Acquisition System interface. By bypassing expected authorization boundaries or abusing improper input validation and access controls within the component, the remote attacker can query or extract sensitive information normally restricted to authorized users. Because of the scope change attribute, the attack execution path may propagate beyond the immediate boundaries of the Content Acquisition System, potentially exposing interconnected systems or shared data repositories. Post-exploitation impact is strictly centered around unauthorized data disclosure, allowing the adversary to exfiltrate critical data assets accessible to the affected application stack."
}