A critical, easily exploitable vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated attacker to fully compromise the product over the network, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-61145 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (part of Oracle Commerce). Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful exploitation can result in a complete takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges, and no user interaction, means it can be exploited remotely with no authentication and minimal effort. The impact is severe across all three pillars: high confidentiality, high integrity, and high availability. Because the outcome is a product takeover, a successful attack gives full control over the affected instance.
What's Vulnerable
The affected supported version is Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0, from Oracle Corporation. The vulnerable component is the Content Acquisition System within Oracle Commerce.
Patch Status
Oracle addressed this issue in its Critical Patch Update for July 2026 (cpujul2026.html). Organizations running the affected 11.4.0 version should consult Oracle's Critical Patch Update advisory and apply the associated fixes without delay, given the unauthenticated, network-based nature of the flaw. As of this record, the CVE was published on 2026-07-21 with a vulnerability status of "Received," and there is no CISA KEV entry supplied confirming active exploitation.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD – CVE-2026-61145; https://nvd.nist.gov/vuln/detail/CVE-2026-61145