Summary
CVE-2026-71024 is a high-severity vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Forge component. Oracle rates it "easily exploitable," allowing an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data and cause partial denial of service. The flaw carries a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: a flaw in the Forge component of Oracle Commerce Guided Search / Experience Manager that fails to properly restrict access to critical data.
- Trigger conditions: no authentication or user interaction is required; the attacker only needs HTTP network access to the exposed Forge component.
- Attack vector: Network (AV:N), Low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact (unauthorized access to critical data) and Low availability impact (partial denial of service); no integrity impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 (component: Forge).
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update (CSPU) for Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.
- If patching cannot be applied immediately: restrict network access to the Forge component so it is not reachable from untrusted networks, and monitor for anomalous HTTP requests against Oracle Commerce Guided Search / Experience Manager endpoints until the patch can be deployed.

