SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61156 2026-07-21

Oracle Commerce Guided Search Hit by Critical Unauthenticated Data Compromise Flaw (CVE-2026-61156)

"CVE-2026-61156 is a critical (CVSS 9.1) vulnerability in Oracle Commerce Guided Search Platform Services that lets an unauthenticated, network-based attacker read and alter critical data without any user interaction."

CVE-2026-61156 is a critical (CVSS 9.1) vulnerability in Oracle Commerce Guided Search Platform Services that lets an unauthenticated, network-based attacker read and alter critical data without any user interaction.

What Is It

CVE-2026-61156 is a vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce, in the Forge component. According to Oracle's disclosure, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTPS to compromise the affected service. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or of all data accessible to Guided Search Platform Services, as well as unauthorized read access to that same critical data. It carries a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.

Why It Matters

The vector tells the story: network attack vector, low complexity, no privileges, and no user interaction required. That combination means an attacker only needs reachability over HTTPS to exploit it. The impact is High for both confidentiality and integrity, so attackers can both exfiltrate and tamper with critical data. There is no availability impact. Because Guided Search underpins product discovery in e-commerce deployments, tampering or data theft here can directly affect customer-facing storefronts.

What's Vulnerable

No other affected CPEs are listed in the supplied NVD record.

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running Oracle Commerce Guided Search Platform Services 11.4.0 should apply the fixes referenced in the Oracle security alert. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material; the NVD record status is "Received."

Sources