Sceawere
Vulnerability Detail
CVE-2026-71009UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Experience Manager Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-08-18T21:18:00.190Z",
"pubdate": "2026-08-18T21:18:00.190Z",
"executiveSummary": "This vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Experience Manager component in version 11.4.0. It is classified as a difficult to exploit vulnerability that can be leveraged by an unauthenticated attacker with network access via HTTP to compromise the targeted system.\nSuccessful exploitation of this security flaw can lead to unauthorized creation, deletion, or modification access to critical data, as well as complete unauthorized access to all accessible data within Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The vulnerability impacts both confidentiality and integrity, yielding a CVSS 3.1 Base Score of 7.4 with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N.\nThe risk implications are significant due to the potential exposure and manipulation of critical enterprise data. Attackers require network connectivity via HTTP, and while exploitation is characterized as difficult, the lack of required authentication or user interaction broadens the threat landscape for exposed instances.",
"technicalDetails": "The vulnerability resides within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw allows unauthenticated remote actors to interact with vulnerable endpoints over the HTTP protocol, bypassing security controls designed to restrict access to sensitive application functions and underlying data stores.\nThe attack vector is network-based (AV:N), meaning the vulnerable interface is accessible over a network without requiring physical access or local system presence. The attack complexity is rated as high (AC:H), indicating that successful exploitation likely requires specific preconditions, precise timing, or non-trivial configuration handling by the attacker to bypass defensive mechanisms. Zero privileges are required (PR:N) and no user interaction is necessary (UI:N), allowing automated or direct manual exploitation attempts once the network path is established.\nDuring the attack flow, an unauthenticated adversary crafts specialized HTTP requests directed at the vulnerable Experience Manager component. Due to insufficient input validation, authorization checks, or access control enforcement within the affected component, the malicious payload is processed by the application. This permits the attacker to interact with backend data structures outside their intended privilege scope.\nThe post-exploitation impact encompasses severe breaches of confidentiality (C:H) and integrity (I:H). An attacker can read critical or all accessible data stored within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager ecosystem. Furthermore, the attacker gains unauthorized write capabilities, enabling the creation, modification, or deletion of critical data assets. Availability remains unaffected (A:N), as the vulnerability does not inherently cause denial-of-service conditions."
}