Sceawere

Vulnerability Detail

CVE-2026-70993UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:58.310Z",
  "pubdate": "2026-08-18T21:17:58.310Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically affecting the Content Acquisition System component in version 11.4.0. This security flaw allows unauthenticated remote attackers with network access via HTTP to compromise the affected software without requiring user interaction.\nSuccessful exploitation of this vulnerability has severe operational implications, resulting in an unauthorized ability to cause a complete denial of service through an application hang or frequently repeatable crash. Furthermore, successful attacks grant unauthorized update, insert, or delete access to a subset of data accessible by the application, directly impacting data integrity and availability.\nGiven the network-based attack vector, low attack complexity, and lack of authentication requirements, the vulnerability carries a CVSS 3.1 Base Score of 8.2 with the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). The risk implication is high, necessitating immediate administrative focus to secure the affected environment against potential disruption and unauthorized data manipulation.",
  "technicalDetails": "The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from improper input validation or insufficient request handling logic within the HTTP interface exposed by the vulnerable component, which fails to securely process specific incoming network payloads.\nExploitation is conducted remotely over the network using the HTTP protocol. Because the vulnerability requires no authentication and no user interaction, an unauthenticated attacker can directly interact with the exposed endpoints of the Content Acquisition System. The attack complexity is low, meaning standard network access is sufficient to consistently deliver the malicious payload without advanced evasion techniques.\nThe step-by-step attack flow begins with the attacker establishing network connectivity to the HTTP service hosting the Content Acquisition System. The attacker then transmits a maliciously crafted HTTP request designed to trigger the underlying flaw in the request processing pipeline. Upon receipt and parsing of the payload, the application enters an unstable state or encounters an unhandled exception.\nThis behavior manifests in two distinct post-exploitation impacts. First, the application resources become exhausted or deadlocked, leading to a complete denial of service characterized by a system hang or a repeatable application crash. Second, the crafted interaction abuses logic flaws to execute unauthorized data modification operations, specifically resulting in unauthorized update, insert, or delete access to accessible data within the scope of the Content Acquisition System.\nThe vulnerability affects the integrity and availability security metrics while leaving confidentiality unimpacted. The scope remains unchanged (S:U) as the vulnerability impacts solely the local component environment without directly crossing trust boundaries into underlying operating system resources."
}
CVE-2026-70993: Oracle Commerce Denial of Service (HIGH Severity, CVSS: 8.2) - Sceawere