CRITICAL 9.1 CVE-2026-70978 Published 18 Aug 2026

Oracle Commerce Guided Search and Experience Manager Unauthorized Data Access Flaw

Worried this affects one of your servers?

A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Content Acquisition System component. The affected version is 11.4.0.

The flaw is an easily exploitable unauthorized data access and modification vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the product.

  • Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all accessible data.
  • It can also lead to unauthorized access to critical data or complete access to all accessible data.
  • CVSS 3.1 Base Score is 9.1, with Confidentiality and Integrity impacts.

Reference: CVE-2026-70978 on NVD

← Back to Security News