CRITICAL 9.1 CVE-2026-70979 Published 18 Aug 2026

Oracle Commerce Guided Search/Experience Manager Critical Data Integrity and DoS Flaw

Worried this affects one of your servers?

A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Content Acquisition System component. The affected supported version is 11.4.0.

The flaw is an easily exploitable data integrity and denial of service vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the product.

  • Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all accessible data.
  • It can also cause a hang or frequently repeatable crash (complete denial of service).
  • CVSS 3.1 Base Score is 9.1, with Integrity and Availability impacts.
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

Reference: CVE-2026-70979 on NVD

← Back to Security News