A critical, easily exploitable vulnerability in Oracle Commerce Guided Search Platform Services lets unauthenticated remote attackers access sensitive data and crash the service, earning a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-61155 is a critical vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services (part of Oracle Commerce). It allows an unauthenticated attacker with network access via HTTP to compromise the platform. The flaw is rated CVSS 3.1 base score 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H, network attack vector, low complexity, no privileges, and no user interaction required.
Why It Matters
Successful exploitation can result in unauthorized access to critical data, up to complete access to all data accessible by Oracle Commerce Guided Search Platform Services (high confidentiality impact). It can also cause a hang or frequently repeatable crash; a complete denial of service (high availability impact). Because the attack requires no authentication and no user interaction and is described as "easily exploitable" over HTTP, the barrier to exploitation is low. There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the source material.
What's Vulnerable
- Product: Oracle Commerce Guided Search Platform Services (Oracle Commerce)
- Component: Forge
- Vendor: Oracle Corporation
- Affected version: 11.4.0
Patch Status
Oracle references this vulnerability in its July 2026 Critical Patch Update advisory. Organizations running the affected version should consult the Oracle Critical Patch Update (cpujul2026) for remediation guidance and apply the vendor-provided fixes. No CISA KEV required-action or due date is present in the supplied data.