Oracle disclosed CVE-2026-61154, a critical (CVSS 9.8) flaw in the Forge component of Oracle Commerce Guided Search Platform Services that lets an unauthenticated attacker fully compromise the service over the network.
What Is It
CVE-2026-61154 is a vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services, part of Oracle Commerce. Per Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise the affected service. Successful exploitation can result in a complete takeover of Oracle Commerce Guided Search Platform Services.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges, and no user interaction required, means it can be triggered remotely by anyone who can reach the service over HTTP. Impacts to confidentiality, integrity, and availability are all rated High, reflecting the potential for full service takeover.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Commerce Guided Search Platform Services (Oracle Commerce)
- Component: Forge
- Affected version: 11.4.0
Patch Status
The CVE was published on 2026-07-21 with an NVD status of "Received." Oracle addressed the issue in its July 2026 Critical Patch Update; administrators should consult that advisory and apply the associated fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61154, https://nvd.nist.gov/vuln/detail/CVE-2026-61154