Sceawere

Vulnerability Detail

CVE-2026-70990UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-18T21:17:57.980Z",
  "pubdate": "2026-08-18T21:17:57.980Z",
  "executiveSummary": "A vulnerability exists within the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, which allows unauthenticated remote attackers to compromise the system.\nThis flaw presents a significant risk to confidentiality, potentially granting unauthorized access to critical data or complete access to all accessible data within the targeted application.\nAlthough the vulnerability resides natively within Oracle Commerce Guided Search / Oracle Commerce Experience Manager, successful exploitation introduces a scope change that may severely impact supplementary and integrated enterprise products.\nThe attack vector relies on network access via HTTP, requiring no user interaction or prior authentication, though the exploitation complexity is rated as high.\nOrganizations utilizing the affected software version must prioritize remediation actions to prevent potential data exposure and unauthorized intelligence gathering by malicious actors.",
  "technicalDetails": "The vulnerability affects the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.\nExploitation of this flaw is carried out remotely over the network utilizing the HTTP protocol, requiring no prior authentication or user interaction from the target environment.\nThe attack vector is classified with a high attack complexity metric, indicating that specific preconditions or precise timing may be necessary for an attacker to successfully execute the payload and bypass protective mechanisms.\nThe technical root cause enables unauthorized extraction of sensitive information, resulting in complete confidentiality impact against data accessible by the Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance.\nDue to a scope change (S:C), a successful exploit is not strictly confined to the boundaries of the primary vulnerable component; the security impact extends beyond the immediate application context to potentially compromise additional integrated products within the broader architecture.\nDuring the attack flow, an unauthenticated remote adversary crafts and transmits specialized HTTP requests directed at the vulnerable Content Acquisition System interface.\nUpon successful processing of the crafted payload by the application, the system improperly discloses restricted information, leading to unauthorized read access to critical enterprise data repositories and associated assets.\nThe CVSS 3.1 vector is defined as CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N, reflecting a base score of 6.8 with high confidentiality impact, zero integrity impact, and zero availability impact."
}
CVE-2026-70990: Oracle Commerce Guided Search Information Disclosure (MEDIUM Severity, CVSS: 6.8) - Sceawere