Sceawere

Vulnerability Detail

CVE-2026-71001UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Experience Manager Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:17:59.247Z",
  "pubdate": "2026-08-18T21:17:59.247Z",
  "executiveSummary": "A vulnerability has been identified within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This security flaw enables a remote, low-privileged attacker with network access via the HTTP protocol to compromise the system and achieve unauthorized access to sensitive information. The vulnerability exclusively impacts confidentiality, resulting in potential exposure of critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The CVSS 3.1 base score is 6.5, reflecting a significant risk to data privacy and integrity within the application ecosystem. Exploitation requires low privileges and network connectivity, but does not require user interaction, making it accessible to authenticated internal users or compromised accounts. Successful exploitation allows threat actors to harvest sensitive operational or customer data processed by the targeted search and merchandising platform.",
  "technicalDetails": "The vulnerability resides in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient access controls or improper authorization enforcement within the HTTP request handling logic of the affected component, allowing users with low privileges to query and retrieve restricted datasets outside their intended scope.\nThe attack flow begins when a low-privileged authenticated attacker leverages network access via the HTTP protocol to interact with the vulnerable Oracle Commerce Guided Search / Oracle Commerce Experience Manager endpoints. Because input validation or authorization checks are inadequately enforced on specific application functions within the Experience Manager component, the attacker can craft malicious HTTP requests or manipulate parameters to bypass logical access boundaries.\nUpon transmitting the crafted HTTP request to the target server, the vulnerable component processes the input without properly validating whether the requesting user possesses the necessary administrative or high-privilege authorization to access the requested records. The backend application then executes the query and returns the sensitive dataset within the HTTP response payload.\nPost-exploitation impact is strictly confined to confidentiality degradation, where the attacker gains unauthorized read access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The attack vector is strictly network-based (AV:N), attack complexity is low (AC:L), privileges required are low (PR:L), and user interaction is not required (UI:N), resulting in a scope-unchanged (S:U) vulnerability with high confidentiality impact (C:H)."
}
CVE-2026-71001: Oracle Commerce Experience Manager Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere