Summary
CVE-2026-70976 is a critical vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting the Content Acquisition System component. It allows an unauthenticated attacker with network access via HTTP to make unauthorized changes to critical data (create, delete, or modify) and to cause a denial of service, without requiring any credentials or user interaction. Oracle rates the issue 9.1 (CRITICAL) on CVSS v3.1.
Technical details
- Root cause: A flaw in the Content Acquisition System component of Oracle Commerce Guided Search / Experience Manager permits unauthorized data manipulation.
- Trigger conditions: No authentication or user interaction is required; the flaw is reachable over HTTP.
- Attack vector: Network (remote), low attack complexity, no privileges required.
- Impact: High integrity impact (unauthorized creation, deletion, or modification of critical data) and high availability impact (denial of service); no confidentiality impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 9.1 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update advisory for Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0.
- If patching cannot be performed immediately: Restrict network access to the Content Acquisition System component to trusted internal hosts only, and monitor HTTP traffic to the affected service for unexpected data-modification requests until the patch can be applied.

