CRITICAL 9 CVE-2026-70980 Published 18 Aug 2026

Oracle Commerce Guided Search and Experience Manager Remote Takeover Vulnerability

Worried this affects one of your servers?

A vulnerability has been disclosed in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Content Acquisition System). The flaw is a remote takeover vulnerability affecting version 11.4.0.

The issue is difficult to exploit and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in full takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, and the impact may extend to additional products due to scope change.

  • Affected version: 11.4.0
  • Attack conditions: unauthenticated, network access via HTTP, difficult to exploit
  • Impact: takeover of the affected Oracle Commerce product; scope change to additional products
  • CVSS 3.1 Base Score: 9.0 (Confidentiality, Integrity, and Availability impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

Reference: CVE-2026-70980 on NVD

← Back to Security News