CRITICAL
9.1 CVE-2026-70977 Published 18 Aug 2026
Oracle Commerce Guided Search and Experience Manager Flaw Enables Data Tampering and DoS
Worried this affects one of your servers?
Vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Content Acquisition System). The supported affected version is 11.4.0.
This easily exploitable unauthenticated HTTP vulnerability allows an attacker with network access to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, and can cause a hang or frequently repeatable crash (complete DoS).
- Affected version: 11.4.0
- CVSS 3.1 Base Score: 9.1 (Integrity and Availability impacts)
- CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Reference: CVE-2026-70977 on NVD
← Back to Security News