CRITICAL
9.1 CVE-2026-70976 Published 18 Aug 2026
Oracle Commerce Guided Search Flaw Enables Data Tampering and DoS
Worried this affects one of your servers?
A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Content Acquisition System component.
The supported affected version is 11.4.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP.
- Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all accessible data.
- Attacks can also cause a hang or frequently repeatable crash, resulting in a complete denial of service.
- CVSS 3.1 base score is 9.1, with Integrity and Availability impacts.
Reference: CVE-2026-70976 on NVD
← Back to Security News