CRITICAL
9.1 CVE-2026-70984 Published 18 Aug 2026
Oracle Commerce Guided Search/Experience Manager Unauthenticated Data Integrity and DoS Flaw
Worried this affects one of your servers?
A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Content Acquisition System).
The issue is an unauthenticated HTTP vulnerability that allows remote attackers to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, and can cause a complete denial of service.
- Affected version: 11.4.0
- Attack vector: network access via HTTP, no authentication required
- CVSS 3.1 base score: 9.1 (Integrity and Availability impacts)
- CVSS vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Reference: CVE-2026-70984 on NVD
← Back to Security News