Sceawere

Vulnerability Detail

CVE-2026-71036UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Experience Manager Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:18:03.313Z",
  "pubdate": "2026-08-18T21:18:03.313Z",
  "executiveSummary": "A critical security vulnerability has been identified within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically residing in the Experience Manager component. This flaw impacts the supported version 11.4.0 and presents a severe risk to organizational data security and integrity. The vulnerability is characterized by its high severity, carrying a CVSS 3.1 Base Score of 9.1 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, highlighting significant confidentiality and integrity impact without affecting system availability.\nThe primary risk implication of this security issue is the exposure of sensitive data alongside unauthorized data manipulation capabilities. An attacker can leverage this flaw to gain unauthorized access to critical data or complete access to all accessible data within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment. Furthermore, successful exploitation grants the adversary unauthorized capabilities to create, delete, or modify critical data or all accessible repository data.\nCrucially, the vulnerability requires minimal attacker capabilities for successful exploitation. It is classified as easily exploitable, allowing an unauthenticated attacker to compromise the target system remotely. Interaction from a user is not required, and the attack vector is network-based, meaning exploitation can occur entirely over HTTP without prior credentials or privileged access within the application.",
  "technicalDetails": "The security flaw exists within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient access controls, input validation, or authorization enforcement mechanisms within the application endpoints exposed over the HTTP protocol. Because the affected component fails to properly validate the identity and authorization context of incoming requests, remote adversaries can interact directly with sensitive backend logic and data storage mechanisms.\nRegarding exploitation requirements and attack vectors, the vulnerability is exposed via network access over HTTP. The attack complexity is rated as low (AC:L), indicating that no specialized race conditions, memory corruption tuning, or complex pre-conditions are required to achieve reliable exploitation. The attack vector is network-based (AV:N), meaning any system capable of communicating with the target over HTTP can initiate an attack. Crucially, the vulnerability demands no privileges (PR:N) and zero user interaction (UI:N), allowing automated scripts or unauthenticated malicious actors to execute the attack flow seamlessly.\nThe step-by-step attack flow proceeds as follows: First, the unauthenticated attacker establishes a network connection to the target Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance via HTTP. Second, the adversary crafts malicious HTTP requests targeted at the vulnerable Experience Manager component, bypassing expected authentication and authorization gates due to the lack of adequate request validation. Third, the application processes the incoming request, treating the unauthenticated input as a legitimate, authorized operation. Finally, depending on the payload injected by the attacker, the application executes unauthorized data read operations leading to critical information disclosure, or unauthorized data write, update, and delete operations leading to integrity compromise across the accessible datasets.\nThe post-exploitation impact is substantial. From a confidentiality perspective, the attacker achieves unauthorized access to critical data and potentially complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. From an integrity perspective, the adversary can perform unauthorized creation, modification, and deletion of critical or total system data. The scope (S:U) remains unchanged, indicating that the vulnerability impacts resources strictly within the security authority of the vulnerable application component, while availability (A:N) remains unaffected, ensuring the service continues to run despite the data compromise."
}
CVE-2026-71036: Oracle Commerce Experience Manager Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere