CRITICAL
9.1 CVE-2026-71036 Published 18 Aug 2026
Oracle Commerce Guided Search / Experience Manager Unauthorized Data Access Vulnerability
Worried this affects one of your servers?
A vulnerability has been found in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Experience Manager). The flaw is an unauthorized data access vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the product.
The supported affected version is 11.4.0. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all accessible data.
- Affected version: 11.4.0
- Attack vector: network via HTTP
- Authentication: none required
- CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)
Reference: CVE-2026-71036 on NVD
← Back to Security News