Oracle disclosed a critical (CVSS 9.9) vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager that lets a low-privileged, network-based attacker fully take over the affected product.
What Is It
CVE-2026-61146 is a vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, part of Oracle Commerce. Oracle rates it "easily exploitable": an attacker with low privileges and network (HTTP) access can compromise the product without user interaction. Successful exploitation results in complete takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. It carries a CVSS 3.1 base score of 9.9 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The flaw scores 9.9, near the top of the critical range, because of low attack complexity, network reach, and full confidentiality, integrity, and availability impact. Critically, the scope is changed (S:C): while the vulnerability lives in Guided Search / Experience Manager, Oracle notes attacks "may significantly impact additional products," meaning compromise can extend beyond the vulnerable component itself. The combination of low required privileges and no user interaction makes this an attractive target once details are public.
What's Vulnerable
- Product: Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Oracle Commerce)
- Component: Content Acquisition System
- Affected version: 11.4.0
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators running the affected 11.4.0 release should apply the fixes referenced in Oracle's CPU advisory. This CVE does not currently appear in the supplied CISA KEV data, so there is no confirmation of active exploitation at this time; given the 9.9 severity and ease of exploitation, prompt patching is strongly advised.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61146, https://nvd.nist.gov/vuln/detail/CVE-2026-61146