Sceawere
Vulnerability Detail
CVE-2026-70984UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search CAS Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-08-18T21:17:57.293Z",
"pubdate": "2026-08-18T21:17:57.293Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This flaw allows unauthenticated remote attackers with network access via HTTP to interact with the vulnerable application and execute unauthorized operations. The vulnerability carries a CVSS 3.1 Base Score of 9.1, reflecting severe impacts on the integrity and availability of the system. Successful exploitation enables malicious actors to perform unauthorized creation, deletion, or modification of critical data, as well as induce a complete denial of service through application hangs or repeatable crashes. The risk implications are critical, as the vulnerability requires no privileges, no user interaction, and can be exploited remotely over standard network protocols, exposing enterprise e-commerce infrastructures to significant data tampering and operational disruption.",
"technicalDetails": "The vulnerability resides within the Content Acquisition System (CAS) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. The root cause stems from insufficient validation and access controls within the network-exposed HTTP interface, allowing unauthenticated client interactions to bypass security boundaries. An attacker initiates the attack flow by sending crafted HTTP requests directly to the vulnerable Content Acquisition System service over the network without requiring any prior authentication or user interaction. Due to the low complexity (AC:L) of the attack vector, the malicious payload is processed by the underlying vulnerable functions of the component, which fail to properly sanitize input or restrict sensitive API operations.\nUpon successful processing of the malicious payload, the post-exploitation impact manifests in two primary vectors: data integrity compromise and service availability degradation. For integrity, the attacker gains unauthorized capabilities to create, modify, or delete critical enterprise data managed by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. For availability, the payload triggers resource exhaustion, unhandled exceptions, or fatal application states, resulting in a complete denial of service characterized by application hangs or frequently repeatable crashes of the service. The attack vector is strictly network-based (AV:N), requiring no privileges (PR:N) and no user interaction (UI:N), while maintaining an unchanged scope (S:U) as defined by the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)."
}