Summary
CVE-2026-70977 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the component, leading to unauthorized modification of data and denial-of-service conditions. Oracle rates the issue 9.1 (Critical) on the CVSS v3.1 scale and disclosed it in the August 2026 Critical Security Patch Update.
Technical details
- Root cause: A flaw in the Content Acquisition System component of Oracle Commerce Guided Search / Experience Manager that permits unauthorized actions without authentication.
- Trigger conditions: The affected component must be reachable over the network via HTTP; no credentials or user interaction are required.
- Attack vector: Network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High integrity impact (unauthorized creation, deletion, or modification of critical data) and high availability impact (denial-of-service/system crash); no confidentiality impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Security Patch Update for Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0.
- If patching cannot be applied immediately: Restrict network access to the Content Acquisition System component so it is not reachable from untrusted networks, and monitor exposed Oracle Commerce instances for unusual HTTP requests until the patch is applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- HTTP response header
x-atg-version: value matchingATGPlatform/followed by a version number - Raw response body (HTML): presence of an element attribute containing
_dyncharset

