Sceawere
Vulnerability Detail
CVE-2026-70997UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Experience Manager Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-08-18T21:17:58.767Z",
"pubdate": "2026-08-18T21:17:58.767Z",
"executiveSummary": "A critical security vulnerability has been identified within the Oracle Commerce Guided Search and Oracle Commerce Experience Manager product, specifically targeting the Experience Manager component in version 11.4.0. This remotely exploitable vulnerability allows unauthenticated attackers with network access via the HTTP protocol to compromise the targeted system without requiring user interaction or prior privileges. Successful exploitation of this flaw can lead to severe operational and data security consequences, including unauthorized access to critical or complete datasets managed by the application, as well as the ability to trigger a denial of service condition characterized by application hangs or repeatable crashes. The severity of this vulnerability is underscored by a CVSS 3.1 Base Score of 9.1, reflecting high impacts on both confidentiality and availability. The ease of exploitation combined with the lack of authentication requirements presents a significant risk to organizations deploying the affected version, making prompt risk assessment and mitigation implementation imperative for maintaining enterprise security posture and business continuity.",
"technicalDetails": "The vulnerability resides within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw is exposed via the application's network interface, accessible over the HTTP protocol, and can be triggered remotely without any form of authentication or user interaction, as indicated by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H. The attack flow begins when an unauthenticated malicious actor transmits a specially crafted HTTP request directly to the vulnerable Experience Manager endpoint. Due to insufficient input validation, improper access control enforcement, or flawed request processing logic within the component, the application fails to properly handle the incoming payload. This triggers a breakdown in data handling or resource management. In terms of confidentiality impact, the exploitation mechanism allows the attacker to bypass security boundaries, granting unauthorized read access to critical application data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Regarding availability impact, the processing of the malicious payload induces a fatal exception, resource exhaustion, or deadlock condition within the application runtime, resulting in a complete denial of service characterized by application hangs or frequently repeatable crashes. The low attack complexity indicates that no specialized reconnaissance or advanced exploitation prerequisites are required for a threat actor to successfully compromise the targeted system."
}