CRITICAL
9.3 CVE-2026-71037 Published 18 Aug 2026
Oracle Commerce Experience Manager HTTP Vulnerability Allows Unauthorized Data Access
Worried this affects one of your servers?
Vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Experience Manager). The supported affected version is 11.4.0.
The flaw is an HTTP-based access and data integrity vulnerability that is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful attacks require human interaction from a person other than the attacker.
Attacks may significantly impact additional products (scope change) and can result in:
- Unauthorized creation, deletion, or modification of critical data or all accessible Oracle Commerce Guided Search / Oracle Commerce Experience Manager data
- Unauthorized access to critical data or complete access to all accessible Oracle Commerce Guided Search / Oracle Commerce Experience Manager data
CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Reference: CVE-2026-71037 on NVD
← Back to Security News