Sceawere

Vulnerability Detail

CVE-2026-71010UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Experience Manager Takeover Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-18T21:18:00.310Z",
  "pubdate": "2026-08-18T21:18:00.310Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Experience Manager component in version 11.4.0. This security flaw enables an unauthenticated attacker who has obtained logon access to the underlying execution infrastructure to compromise the application entirely. Successful exploitation requires human interaction from an individual other than the attacker, emphasizing the reliance on a victim triggering a specific user-assisted action within the environment.\nThe implications of a successful attack are severe, resulting in the complete takeover of the Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance. This leads to high impacts across all three pillars of the CIA triad: Confidentiality, Integrity, and Availability. Given the CVSS 3.1 Base Score of 7.8, organizations utilizing the affected version face significant operational and security risks if the host infrastructure is not adequately hardened against unauthorized local access and malicious user interactions.",
  "technicalDetails": "The vulnerability resides in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. According to the CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), the attack vector is local (AV:L), meaning the adversary must already possess logon capabilities to the infrastructure where the affected product executes. The attack complexity is low (AC:L), indicating that once the prerequisite conditions are met, the exploitation mechanics do not require intricate or highly specialized techniques. Furthermore, the vulnerability requires no explicit privileges (PR:N) from the attacker's perspective on the application itself, but it strictly mandates user interaction (UI:R) from a third party to successfully finalize the exploit chain.\nThe attack flow begins with the unauthenticated attacker establishing a foothold or leveraging existing logon access to the host infrastructure hosting the Oracle Commerce Guided Search / Oracle Commerce Experience Manager service. Because the vulnerability requires human interaction, the attacker typically engineers a scenario where a legitimate user or administrator interacts with a manipulated component, file, or interface within the execution environment. This interaction triggers the vulnerable code path in the Experience Manager component.\nUpon successful triggering of the flaw via user interaction, the exploitation payload executes within the context of the application. The post-exploitation impact is catastrophic, resulting in a full system or application takeover. This grants the attacker the ability to read, modify, or exfiltrate sensitive data affecting confidentiality, alter application logic and underlying data structures impacting integrity, and disrupt service availability. The scope is unmodified (S:U), confining the direct impact to the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product instance residing on the compromised infrastructure."
}
CVE-2026-71010: Oracle Commerce Experience Manager Takeover Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere