Sceawere
Vulnerability Detail
CVE-2026-71034UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Forge SOAP Information Disclosure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:18:03.080Z",
"pubdate": "2026-08-18T21:18:03.080Z",
"executiveSummary": "A vulnerability has been identified in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Forge component affecting version 11.4.0. This flaw presents a significant risk to organizational data security by allowing remote, unauthenticated threat actors to leverage network access via the SOAP protocol to compromise the targeted system. Successful exploitation of this vulnerability results in unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, with impact strictly limited to confidentiality. The vulnerability carries a CVSS 3.1 Base Score of 7.5, reflecting its severity due to the absence of authentication requirements, low attack complexity, and network vector accessibility. Attackers require no prior privileges or user interaction to successfully execute malicious operations against the affected system. Mitigation requires applying vendor-supplied updates or implementing strict network access controls to limit exposure of vulnerable SOAP endpoints.",
"technicalDetails": "The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient validation, access control enforcement, or improper handling of incoming requests processed through the SOAP protocol interface exposed by the application. Because the affected service is exposed via network interfaces and lacks mandatory authentication mechanisms, remote attackers can interact directly with the SOAP endpoints without possessing valid credentials or session tokens.\nThe attack flow begins when an unauthenticated threat actor constructs a maliciously crafted SOAP request targeted at the vulnerable network service provided by the Forge component. The attacker transmits this payload over the network via the SOAP protocol, bypassing authentication layers due to the lack of proper access controls in version 11.4.0. Upon receipt, the vulnerable component processes the incoming SOAP messages without adequately verifying the caller's authorization to retrieve the requested information. This flaw permits unauthorized execution of internal functions or data queries handled by Forge.\nPost-exploitation impact is characterized by a high severity compromise of data confidentiality. Once the payload is successfully processed, the system returns sensitive information to the unauthorized requester. This results in unauthorized access to critical data repositories or complete exposure of all data accessible within the scope of the Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployment. The vector is classified as network-based (AV:N), with low attack complexity (AC:L), requiring zero privileges (PR:N) and no user interaction (UI:N), while maintaining an unchanged security scope (S:U). The confidentiality impact is total (C:H), while integrity (I:N) and availability (A:N) remain unaffected."
}