CVE-2026-61156 is a critical (CVSS 9.1) vulnerability in Oracle Commerce Guided Search Platform Services that lets an unauthenticated, network-based attacker read and alter critical data without any user interaction.
What Is It
CVE-2026-61156 is a vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce, in the Forge component. According to Oracle's disclosure, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTPS to compromise the affected service. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or of all data accessible to Guided Search Platform Services, as well as unauthorized read access to that same critical data. It carries a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Why It Matters
The vector tells the story: network attack vector, low complexity, no privileges, and no user interaction required. That combination means an attacker only needs reachability over HTTPS to exploit it. The impact is High for both confidentiality and integrity, so attackers can both exfiltrate and tamper with critical data. There is no availability impact. Because Guided Search underpins product discovery in e-commerce deployments, tampering or data theft here can directly affect customer-facing storefronts.
What's Vulnerable
- Product: Oracle Commerce Guided Search Platform Services (component: Forge)
- Affected version: 11.4.0
No other affected CPEs are listed in the supplied NVD record.
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running Oracle Commerce Guided Search Platform Services 11.4.0 should apply the fixes referenced in the Oracle security alert. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material; the NVD record status is "Received."