Sceawere

Vulnerability Detail

CVE-2026-70989UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:17:57.867Z",
  "pubdate": "2026-08-18T21:17:57.867Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This security flaw enables a low-privileged authenticated attacker with local access to the underlying infrastructure to compromise the application and achieve unauthorized confidentiality impacts.\nThe vulnerability carries a CVSS 3.1 Base Score of 6.5 with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N. A successful exploit results in unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Due to a significant scope change, the impact of a successful attack extends beyond the primary product to significantly affect additional associated products within the infrastructure.\nExploitation requires low privileges and local logon access to the execution environment, with no user interaction required. Organizations running the affected version face high risk regarding data confidentiality and potential cascading compromises across integrated systems.",
  "technicalDetails": "The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. The root cause stems from insufficient access controls or insecure data handling within the affected component, allowing users with minimal privileges to bypass boundary restrictions.\nThe attack vector is local (AV:L), meaning the adversary must already possess valid credentials and a logon session on the underlying infrastructure where the Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance executes. The attack complexity is low (AC:L), requiring minimal preparatory effort or specialized conditions from the threat actor. No user interaction (UI:N) is mandated for the attack to succeed.\nThe step-by-step attack flow involves the low-privileged attacker leveraging their local system access to interact directly with the vulnerable Content Acquisition System component. Because of improper privilege validation or boundary enforcement, the attacker sends specially crafted requests or accesses protected system resources managed by the application. This interaction circumvents intended authorization checks.\nUpon successful exploitation, the vulnerability triggers a scope change (S:C), meaning the security scope extends beyond the immediate boundary of Oracle Commerce Guided Search / Oracle Commerce Experience Manager to impact additional, secondary products and systems sharing the infrastructure or trust domain. The resulting post-exploitation impact is focused strictly on confidentiality (C:H), granting the attacker unauthorized access to critical data or complete access to all data repositories and stores accessible by the application components."
}
CVE-2026-70989: Oracle Commerce Guided Search Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere