Sceawere
Vulnerability Detail
CVE-2026-70986UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Content Acquisition System Information Disclosure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:17:57.530Z",
"pubdate": "2026-08-18T21:17:57.530Z",
"executiveSummary": "A vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Content Acquisition System component, version 11.4.0. This flaw allows an unauthenticated remote attacker with network access via HTTP to bypass security controls and achieve unauthorized read access to sensitive information.\nThe vulnerability poses significant risk to data confidentiality, as successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment. The associated CVSS 3.1 Base Score is 7.5, indicating a high severity rating primarily driven by severe confidentiality impacts.\nExploitation of this vulnerability does not require user interaction or prior authentication. Attackers can leverage standard network connectivity via HTTP to target the exposed service directly, requiring low attack complexity to successfully compromise the confidentiality of the affected Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployment.",
"technicalDetails": "The vulnerability resides within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from improper access control enforcement or missing authentication validation mechanisms within the HTTP request handling pipeline of the affected service.\nThe attack vector is network-based (AV:N), allowing remote adversaries to interact directly with the vulnerable HTTP endpoints exposed by the Content Acquisition System. The attack complexity is rated as low (AC:L) because successful exploitation does not require advanced configuration knowledge, race conditions, or specialized environmental prerequisites.\nAn unauthenticated attacker (PR:N) with standard network reachability can initiate HTTP requests targeting vulnerable interfaces within the Content Acquisition System. Due to the absence of proper authentication and authorization checks, the application processes the incoming requests and returns sensitive data that should otherwise be restricted.\nNo user interaction (UI:N) is required, meaning automated scanning tools or malicious scripts can repeatedly query the vulnerable endpoints without human intervention. The scope (S:U) remains unchanged, as the vulnerability is confined to the authorization boundary of the Oracle Commerce Guided Search / Oracle Commerce Experience Manager application.\nThe post-exploitation impact is strictly localized to confidentiality (C:H), resulting in the unauthorized disclosure of critical data repositories or complete access to all data accessible by the Oracle Commerce Guided Search / Oracle Commerce Experience Manager platform. Integrity (I:N) and Availability (A:N) are not directly impacted by this specific vector, as the flaw does not facilitate data modification, deletion, or denial of service."
}