CVE-2026-71038: High severity Oracle Oracle Commerce Guided Search / Oracle Commerce Experience Manager vulnerability
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployments running the supported affected version 11.4.0 are exposed if an attacker can reach the product over HTTP. No authentication or user interaction is required.
What access does an attacker need to exploit it?
An attacker needs network access to the affected product through HTTP. The attack complexity is low, and the attacker does not need privileges or a user to perform an action.
What is the likely impact of successful exploitation?
Successful exploitation can allow unauthorized access to critical data or complete access to all data accessible through Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The stated impact is confidentiality only; integrity and availability impacts are not indicated.