SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61146 2026-07-21

Oracle Commerce Guided Search Hit by Critical Takeover Flaw (CVE-2026-61146)

"Oracle disclosed a critical (CVSS 9.9) vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager that lets a low-privileged, network-based attacker fully take over the affected product."

Oracle disclosed a critical (CVSS 9.9) vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager that lets a low-privileged, network-based attacker fully take over the affected product.

What Is It

CVE-2026-61146 is a vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, part of Oracle Commerce. Oracle rates it "easily exploitable": an attacker with low privileges and network (HTTP) access can compromise the product without user interaction. Successful exploitation results in complete takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. It carries a CVSS 3.1 base score of 9.9 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

The flaw scores 9.9, near the top of the critical range, because of low attack complexity, network reach, and full confidentiality, integrity, and availability impact. Critically, the scope is changed (S:C): while the vulnerability lives in Guided Search / Experience Manager, Oracle notes attacks "may significantly impact additional products," meaning compromise can extend beyond the vulnerable component itself. The combination of low required privileges and no user interaction makes this an attractive target once details are public.

What's Vulnerable

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators running the affected 11.4.0 release should apply the fixes referenced in Oracle's CPU advisory. This CVE does not currently appear in the supplied CISA KEV data, so there is no confirmation of active exploitation at this time; given the 9.9 severity and ease of exploitation, prompt patching is strongly advised.

Sources