SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61155 2026-07-21

CVE-2026-61155: Critical Unauthenticated Flaw in Oracle Commerce Guided Search

"A critical, easily exploitable vulnerability in Oracle Commerce Guided Search Platform Services lets unauthenticated remote attackers access sensitive data and crash the service, earning a CVSS 3.1 base score of 9.1."

A critical, easily exploitable vulnerability in Oracle Commerce Guided Search Platform Services lets unauthenticated remote attackers access sensitive data and crash the service, earning a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-61155 is a critical vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services (part of Oracle Commerce). It allows an unauthenticated attacker with network access via HTTP to compromise the platform. The flaw is rated CVSS 3.1 base score 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

Successful exploitation can result in unauthorized access to critical data, up to complete access to all data accessible by Oracle Commerce Guided Search Platform Services (high confidentiality impact). It can also cause a hang or frequently repeatable crash; a complete denial of service (high availability impact). Because the attack requires no authentication and no user interaction and is described as "easily exploitable" over HTTP, the barrier to exploitation is low. There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the source material.

What's Vulnerable

Patch Status

Oracle references this vulnerability in its July 2026 Critical Patch Update advisory. Organizations running the affected version should consult the Oracle Critical Patch Update (cpujul2026) for remediation guidance and apply the vendor-provided fixes. No CISA KEV required-action or due date is present in the supplied data.

Sources