Sceawere
Vulnerability Detail
CVE-2026-71019UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Internal operations). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-08-18T21:18:01.327Z",
"pubdate": "2026-08-18T21:18:01.327Z",
"executiveSummary": "A security vulnerability has been identified within the Internal operations component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This easily exploitable vulnerability allows an unauthenticated remote attacker with network access via HTTP to compromise the affected software. Successful exploitation requires human interaction from a victim other than the attacker. Due to a scope change, successful attacks may significantly impact additional products beyond the primary target. The security impact includes unauthorized read, update, insert, or delete access to a subset of accessible data within the application. The vulnerability yields a CVSS 3.1 Base Score of 6.1 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, highlighting risks to confidentiality and integrity without causing availability loss.",
"technicalDetails": "The vulnerability resides in the Internal operations component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The attack vector is network-based (AV:N), allowing remote actors to interact with the HTTP service exposed by the application. The vulnerability exhibits a low attack complexity (AC:L) and requires zero privileges (PR:N), meaning any unauthenticated user can initiate an attack sequence. However, successful exploitation mandates user interaction (UI:R), typically requiring a victim to perform an action such as clicking a maliciously crafted link or navigating to a compromised web page.\nThe exploitation mechanism leverages the network protocol via HTTP to transmit malicious payloads designed to interact with the vulnerable Internal operations component. Because the vulnerability features a scope change (S:C), the impact of a successful attack extends beyond the boundaries of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, potentially compromising additional integrated or co-located products within the deployment architecture.\nUpon successful execution, the attack flow enables unauthorized operations against data accessible to the application. This includes unauthorized read access to a subset of sensitive data (C:L) and unauthorized update, insert, or delete access to data within the system (I:L). The lack of availability impact (A:N) indicates that the service remains operational during and after the exploitation attempt. No specific function names, file paths, or URLs are provided in the baseline description, but the flaw fundamentally stems from improper handling of HTTP-based inputs within the targeted component during internal operations."
}