Summary
CVE-2026-70993 is a high-severity vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. It allows an unauthenticated, remote attacker over HTTP to repeatedly crash or hang the application and to make unauthorized inserts, updates, or deletes to accessible data, without any user interaction. Oracle disclosed the flaw as part of its August 2026 Critical Patch Update, and it carries a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: A flaw in the Content Acquisition System component of Oracle Commerce Guided Search / Experience Manager that is "easily exploitable," per Oracle’s advisory.
- Trigger conditions: No authentication or privileges are required; no user interaction is needed.
- Attack vector: Network-based, delivered via HTTP directly to the Content Acquisition System component.
- Impact: Attackers can cause a hang or a frequently repeatable crash (complete denial of service) and can perform unauthorized update, insert, or delete operations on data accessible to the component. Confidentiality is not affected.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update for Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.
- If patching cannot be performed immediately: Restrict or filter network access to the Content Acquisition System component’s HTTP interface (e.g., via network segmentation, firewall rules, or access control lists) to trusted hosts only, until the patch can be applied.

