CRITICAL
9.1 CVE-2026-70981 Published 18 Aug 2026
Oracle Commerce Guided Search Content Acquisition System Data Integrity and DoS Vulnerability
Worried this affects one of your servers?
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0.
This easily exploitable unauthorized data modification and denial-of-service vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data, and can cause a hang or frequently repeatable crash (complete DoS).
- Affected version: 11.4.0
- Attack vector: network access via HTTP, no authentication required
- CVSS 3.1 Base Score: 9.1 (Integrity and Availability impacts)
- CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Reference: CVE-2026-70981 on NVD
← Back to Security News