Sceawere
Vulnerability Detail
CVE-2026-71038UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Experience Manager Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:18:03.543Z",
"pubdate": "2026-08-18T21:18:03.543Z",
"executiveSummary": "An unauthenticated information disclosure vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Experience Manager component version 11.4.0. This security flaw enables remote attackers with network access via the HTTP protocol to compromise the affected software without requiring any user interaction or prior authentication privileges. Successful exploitation of this vulnerability leads to severe confidentiality impacts, resulting in unauthorized access to critical data or complete data exposure across all accessible records within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment. With a CVSS 3.1 Base Score of 7.5, the risk implications are high due to the low attack complexity and the lack of authentication constraints, making external reconnaissance and data harvesting highly accessible to malicious actors targeting exposed instances over the network.",
"technicalDetails": "The vulnerability resides within the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from improper access controls or insecure data handling mechanisms within the application endpoints exposed over the HTTP protocol. Because the vulnerability is accessible via the network (AV:N) with low attack complexity (AC:L) and requires no privileges (PR:N) or user interaction (UI:N), an attacker can directly interact with vulnerable HTTP handlers or service interfaces without establishing an authenticated session.\nThe attack flow begins when an unauthenticated remote attacker crafts and sends malicious or specially formatted HTTP requests to the exposed Oracle Commerce Guided Search / Oracle Commerce Experience Manager endpoints. Upon receiving the incoming request, the vulnerable Experience Manager component fails to adequately validate the authorization context or restrict data retrieval boundaries. Consequently, the application processes the request and improperly discloses sensitive information residing within the system.\nThe post-exploitation impact is strictly confined to the confidentiality dimension (C:H), as denoted by the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The attacker gains unauthorized read access to critical business data, proprietary records, or complete datasets accessible to the Oracle Commerce Guided Search / Oracle Commerce Experience Manager application layer. Integrity and availability impacts remain unaffected by this specific flaw, meaning data modification, deletion, or denial of service conditions do not directly occur through this vector."
}