SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61153 2026-07-21

CVE-2026-61153: Critical Unauthenticated Flaw in Oracle Commerce Guided Search

"Oracle disclosed a critical (CVSS 9.1) vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager that lets an unauthenticated, remote attacker compromise confidentiality and integrity over HTTP."

Oracle disclosed a critical (CVSS 9.1) vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager that lets an unauthenticated, remote attacker compromise confidentiality and integrity over HTTP.

What Is It

CVE-2026-61153 is a critical vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. According to Oracle's NVD record, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. It carries a CVSS 3.1 base score of 9.1 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to and including all data accessible to the product, as well as unauthorized read access to critical data or complete access to all accessible data. Because the vulnerability requires no authentication and no user interaction and is reachable over the network via HTTP, internet-exposed instances are at meaningful risk. The impact is scoped to high confidentiality and high integrity; availability impact is rated none.

There is no CISA KEV entry in the supplied source material, so active exploitation is not confirmed by KEV at this time.

What's Vulnerable

Patch Status

The vulnerability is addressed in Oracle's Critical Patch Update for July 2026. Administrators running affected Oracle Commerce Guided Search / Experience Manager 11.4.0 deployments should review and apply the fixes documented in Oracle's July 2026 CPU advisory. No separate CISA-mandated required action is present in the supplied source material.

Sources