Sceawere
Vulnerability Detail
CVE-2026-71008UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Experience Manager Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-08-18T21:18:00.073Z",
"pubdate": "2026-08-18T21:18:00.073Z",
"executiveSummary": "An unauthenticated information disclosure vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Experience Manager component version 11.4.0. The vulnerability allows a remote attacker with high privileges and network access via HTTP to compromise the targeted system, resulting in severe confidentiality impacts. Successful exploitation grants unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Due to the scope change vector, successful attacks may significantly impact additional integrated products beyond the immediate vulnerable component. The attack complexity is low, requiring no user interaction, but necessitates high-level privileges within the application context. Organizations utilizing the affected Oracle Commerce version face significant risk of data exposure and must apply appropriate access controls and vendor-supplied updates to mitigate the threat.",
"technicalDetails": "The vulnerability resides within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient access controls and validation mechanisms governing sensitive data retrieval processes within the application framework. The attack vector is strictly network-based, utilizing the HTTP protocol to interact with the vulnerable endpoint exposed by the server. Although the vulnerability originates in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager software, the architectural scope change (S:C) indicates that successful exploitation can propagate security implications across supplementary, interconnected ecosystem products. Exploitation requires an attacker to possess high privileges (PR:H) within the application, implying that an adversary must first compromise an administrative or privileged account, or leverage an existing high-privilege session. The attack flow begins with the authenticated high-privileged attacker submitting a specially crafted HTTP request targeting the vulnerable Experience Manager component. Because the application fails to adequately enforce authorization boundaries or restrict data exposure policies, the server processes the request and returns unauthorized sensitive data. The payload behavior involves querying or extracting sensitive backend data stores accessible to the application context. The post-exploitation impact is exclusively focused on confidentiality, yielding unauthorized access to critical data repositories or complete enumeration of all data reachable by the Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance. The low attack complexity (AC:L) and lack of required user interaction (UI:N) mean that once a high-privileged session is attained, the exploitation steps are straightforward and reliably executed over the network."
}