Sceawere

Vulnerability Detail

CVE-2026-71024UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Forge Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:18:01.927Z",
  "pubdate": "2026-08-18T21:18:01.927Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This network-vector vulnerability allows unauthenticated remote attackers to compromise the system over HTTP without requiring user interaction or elevated privileges. Successful exploitation results in severe confidentiality breaches through unauthorized access to critical or complete data accessible by the application, alongside a partial denial of service impacting system availability. With a CVSS 3.1 Base Score of 8.2, the risk implications are substantial, enabling malicious actors to harvest sensitive data and disrupt operational stability. The vulnerability stems from insufficient access controls and validation within the affected component, making network-based reconnaissance and payload delivery straightforward for threat actors targeting exposed instances.",
  "technicalDetails": "The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause involves inadequate input validation and missing authentication enforcement mechanisms within network-facing HTTP interfaces handled by the vulnerable component. Because the affected software exposes these endpoints over the network (AV:N), an unauthenticated attacker (PR:N) with low attack complexity (AC:L) and no required user interaction (UI:N) can directly interact with the vulnerable service.\nThe attack flow proceeds as follows: First, the remote adversary identifies an exposed instance of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 listening on standard HTTP ports. Second, the attacker crafts malicious HTTP requests targeted at the Forge component without providing any credentials or session tokens. Third, upon receiving the unauthenticated request, the vulnerable component fails to enforce proper authorization checks, improperly parsing and executing the requested operations. Finally, the server processes the input and returns responses containing sensitive data or enters a degraded operational state.\nThe resulting impact is twofold, as defined by the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L). The confidentiality impact is high (C:H), granting the attacker unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Concurrently, the availability impact is low (A:L), allowing the attacker to trigger a partial denial of service condition, disrupting normal processing capabilities of the application. The scope remains unchanged (S:U), as the vulnerability confines its impact to the vulnerable component itself without escalating to underlying host operating system privileges."
}
CVE-2026-71024: Oracle Commerce Forge Information Disclosure (HIGH Severity, CVSS: 8.2) - Sceawere