Sceawere

Vulnerability Detail

CVE-2026-71012UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Experience Manager Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:18:00.537Z",
  "pubdate": "2026-08-18T21:18:00.537Z",
  "executiveSummary": "A security vulnerability has been identified in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Experience Manager component affecting version 11.4.0. This easily exploitable flaw allows a low-privileged attacker with network access via HTTP to interact with the target system and compromise its integrity and availability.\nThe vulnerability carries a CVSS 3.1 Base Score of 7.1, with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L. The primary security impacts include high confidentiality degradation and partial availability disruption. Successful exploitation grants the adversary unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, alongside the capability to trigger a partial denial of service condition.\nGiven the network-based attack vector and low privilege requirements, malicious actors can leverage existing low-level credentials to conduct unauthorized data harvesting and service degradation attacks against vulnerable deployments without requiring user interaction.",
  "technicalDetails": "The vulnerability resides within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The attack vector is strictly network-based utilizing the HTTP protocol, indicating that the flaw is exposed through the web application interface or associated service endpoints managed by the affected component.\nExploitation requires low privileges, meaning an authenticated user with minimal access rights can interact with the vulnerable application layer. The attack complexity is rated as low, and no user interaction is required, allowing for straightforward and repeatable execution by a malicious actor.\nThe step-by-step attack flow begins with the low-privileged attacker establishing network connectivity to the HTTP service hosting the Oracle Commerce Guided Search / Oracle Commerce Experience Manager application. By sending specially crafted HTTP requests targeting the vulnerable Experience Manager component, the attacker bypasses intended authorization boundaries or logic controls enforced by the application.\nUpon successful processing of the malicious payload, the underlying flaw enables the attacker to query, read, or exfiltrate sensitive data repositories managed or accessible by the application, resulting in a severe breach of confidentiality. Simultaneously, the payload execution consumes system resources or disrupts application logic, leading to a partial denial of service condition that degrades the operational availability of Oracle Commerce Guided Search / Oracle Commerce Experience Manager for legitimate users.\nThe scope of the vulnerability is unmodified (S:U), indicating that the impact is constrained to the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component itself rather than extending to core underlying operating system resources or hypervisor layers."
}
CVE-2026-71012: Oracle Commerce Experience Manager Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere