Summary
CVE-2026-70997 is a critical, unauthenticated vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. Oracle describes it as an easily exploitable flaw that allows an attacker with network access via HTTP, and no authentication, to gain unauthorized access to critical data and cause denial-of-service conditions. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: a flaw in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Trigger conditions: exploitable over HTTP by an unauthenticated, remote attacker; no user interaction or privileges required.
- Attack vector: Network (AV:N), Attack Complexity: Low (AC:L).
- Impact: high confidentiality impact (unauthorized access to critical data) and high availability impact (denial-of-service); no integrity impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Security Patch Update (CSPU) for Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.
- If patching cannot be applied immediately, restrict network access to the Experience Manager component to trusted hosts/networks only, and monitor for anomalous unauthenticated HTTP requests against Oracle Commerce Experience Manager endpoints until the patch is applied.

