Summary
CVE-2026-70978 is a critical, unauthenticated vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. The flaw allows an attacker with only network access over HTTP to compromise the system without any credentials or user interaction, resulting in unauthorized creation, deletion, and modification of critical data as well as unauthorized data exposure. Oracle rates the issue CRITICAL with a CVSS v3.1 base score of 9.1.
Technical details
- Root cause: an exploitable weakness in the Content Acquisition System component of Oracle Commerce Guided Search / Experience Manager.
- Trigger conditions: no authentication or user interaction is required; the vulnerability is described by Oracle as easily exploitable.
- Attack vector: remote exploitation over HTTP/network access (AV:N).
- Impact: high confidentiality impact (unauthorized access to data) and high integrity impact (unauthorized creation, deletion, or modification of critical data); no availability impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0.
Severity
- CVSS v3.1 Base Score: 9.1 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s Critical Security Patch Update for August 2026, which addresses CVE-2026-70978 for Oracle Commerce Guided Search / Experience Manager 11.4.0. Organizations should apply the corresponding patch as soon as possible.
- If a patch cannot be applied immediately: restrict network access to the Content Acquisition System component to trusted internal networks only, and monitor exposed Oracle Commerce endpoints for unusual creation/modification/deletion activity until patched.

