Summary
CVE-2026-70981 is a critical, unauthenticated remote vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. It allows a network-based attacker with no credentials to create, delete, or modify data accessible to the application and to cause the system to hang or crash. Oracle disclosed the issue in its August 2026 Critical Patch Update with a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: an easily exploitable flaw in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Trigger conditions: exploitable over HTTP without authentication or user interaction.
- Attack vector: Network (AV:N), Low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: unauthorized creation, deletion, or modification of critical/all Oracle Commerce Guided Search / Experience Manager accessible data (High Integrity impact), and the ability to cause a hang or repeatable crash resulting in complete denial of service (High Availability impact). No confidentiality impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for August 2026, which contains the fix for Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.
- If patching cannot be performed immediately, restrict network access to the Content Acquisition System component to trusted internal hosts only and monitor for anomalous HTTP requests until the patch can be applied.

