Sceawere

Vulnerability Detail

CVE-2026-71007UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Experience Manager Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-18T21:17:59.947Z",
  "pubdate": "2026-08-18T21:17:59.947Z",
  "executiveSummary": "This vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically the Experience Manager component in version 11.4.0. The security flaw allows a highly privileged attacker with network access via the HTTP protocol to compromise the application, resulting in unauthorized access to critical data or complete access to all accessible data within the targeted component.\nThe vulnerability carries a CVSS 3.1 Base Score of 6.8, with impacts exclusively affecting confidentiality (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). Due to the scope change (S:C) characteristic of this vector, a successful exploitation of this vulnerability can significantly impact additional products beyond the immediate boundary of the vulnerable component.\nExploitation requires network connectivity and high privileges, meaning the adversary must already possess authenticated administrative access to interact with the target interface. However, the attack complexity is classified as low, and no user interaction is required. Risk implications center around severe data exposure, potential compromise of secondary systems due to the scope change, and the leakage of sensitive business or customer data stored or processed within the Oracle Commerce ecosystem.",
  "technicalDetails": "The security flaw resides within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The architecture of the affected component fails to properly enforce authorization boundaries or adequately sanitize requests processed via the HTTP protocol, allowing an authenticated entity to query or retrieve restricted data assets.\nThe attack vector is network-based (AV:N), requiring the adversary to establish remote HTTP connectivity to the vulnerable Oracle Commerce Guided Search / Oracle Commerce Experience Manager service. The exploitation method relies on the abuse of administrative interfaces or functionality exposed by the Experience Manager component. Because the attack complexity is low (AC:L) and user interaction is not required (UI:N), an attacker with high privileges (PR:H) can immediately execute the attack sequence without needing to trick external users or bypass complex race conditions.\nThe attack flow proceeds as follows: First, the high-privileged adversary authenticates to the network-accessible Oracle Commerce interface. Second, the attacker issues a crafted HTTP request targeted at the vulnerable Experience Manager component, leveraging administrative privileges to request unauthorized data payloads. Third, the application improperly processes the request and returns sensitive data that the administrative context should not normally access or that crosses security domain boundaries due to the scope change (S:C).\nThe post-exploitation impact is characterized by a complete compromise of confidentiality (C:H) regarding data accessible to Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Because the CVSS vector indicates a scope change (S:C), the compromise is not strictly contained within the vulnerable component itself, meaning that successful exploitation can propagate risks or expose data pertaining to additional integrated products within the broader Oracle Commerce deployment. Integrity (I:N) and availability (A:N) metrics remain unaffected, as the primary vector is restricted to unauthorized information disclosure."
}
CVE-2026-71007: Oracle Commerce Experience Manager Information Disclosure (MEDIUM Severity, CVSS: 6.8) - Sceawere