CRITICAL 9.3 CVE-2026-71037 Published 18 Aug 2026

Oracle Commerce Experience Manager HTTP Vulnerability Allows Unauthorized Data Access

Worried this affects one of your servers?

Vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Experience Manager). The supported affected version is 11.4.0.

The flaw is an HTTP-based access and data integrity vulnerability that is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful attacks require human interaction from a person other than the attacker.

Attacks may significantly impact additional products (scope change) and can result in:

  • Unauthorized creation, deletion, or modification of critical data or all accessible Oracle Commerce Guided Search / Oracle Commerce Experience Manager data
  • Unauthorized access to critical data or complete access to all accessible Oracle Commerce Guided Search / Oracle Commerce Experience Manager data

CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).

Reference: CVE-2026-71037 on NVD

← Back to Security News