SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61154 2026-07-21

CVE-2026-61154: Critical Unauthenticated Takeover in Oracle Commerce Guided Search

"Oracle disclosed CVE-2026-61154, a critical (CVSS 9.8) flaw in the Forge component of Oracle Commerce Guided Search Platform Services that lets an unauthenticated attacker fully compromise the service over the network."

Oracle disclosed CVE-2026-61154, a critical (CVSS 9.8) flaw in the Forge component of Oracle Commerce Guided Search Platform Services that lets an unauthenticated attacker fully compromise the service over the network.

What Is It

CVE-2026-61154 is a vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services, part of Oracle Commerce. Per Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise the affected service. Successful exploitation can result in a complete takeover of Oracle Commerce Guided Search Platform Services.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges, and no user interaction required, means it can be triggered remotely by anyone who can reach the service over HTTP. Impacts to confidentiality, integrity, and availability are all rated High, reflecting the potential for full service takeover.

What's Vulnerable

Patch Status

The CVE was published on 2026-07-21 with an NVD status of "Received." Oracle addressed the issue in its July 2026 Critical Patch Update; administrators should consult that advisory and apply the associated fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources