CRITICAL
9.1 CVE-2026-70997 Published 18 Aug 2026
Oracle Commerce Experience Manager Unauthenticated Data Access and DoS Vulnerability
Worried this affects one of your servers?
A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Experience Manager). The flaw is an unauthenticated data access and denial of service issue that can be exploited over HTTP.
An unauthenticated attacker with network access can compromise the affected product, leading to unauthorized access to critical data or complete access to all accessible data, as well as the ability to cause a hang or frequently repeatable crash (complete DoS).
- Affected version: 11.4.0
- CVSS 3.1 Base Score: 9.1 (Confidentiality and Availability impacts)
- Attack vector: Network via HTTP, no authentication required
Reference: CVE-2026-70997 on NVD
← Back to Security News