CVE-2026-61146: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle C...
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Security readout for executives and security teams
Plain-English summary
A low-privileged attacker who can reach the affected service over HTTP may take over Oracle Commerce Guided Search / Oracle Commerce Experience Manager. A successful compromise could expose or alter data, disrupt service, and affect connected products. Only supported version 11.4.0 is identified as affected.
Executive priority
Treat this as an urgent remediation item for any confirmed 11.4.0 deployment. Prioritize externally reachable or business-critical instances because compromise could enable full application takeover and affect connected systems. If the product is absent, document that finding and continue routine vulnerability monitoring.
Technical view
CVE-2026-61146 affects the Content Acquisition System component in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. It is network-accessible, low complexity, requires low privileges, and needs no user interaction. The scope-change rating indicates compromise may cross a security boundary. Successful exploitation can cause complete confidentiality, integrity, and availability impact.
Likely exposure
Exposure is likely where version 11.4.0 is deployed, reachable over HTTP, and accessible to low-privileged accounts. Internet exposure increases concern, but the sources do not state that internet access is required. Other versions and products are not confirmed as directly affected.
Exploitation context
The CVSS score is 9.9 because exploitation is described as easy and can produce takeover with broader impact. The supplied record is not listed in KEV, and the cited sources provide no evidence of active exploitation or public exploit availability.
Researcher notes
The public description maps to improper privilege or access-control weaknesses, including CWE-269, CWE-284, and CWE-306. However, it does not disclose the vulnerable endpoint, root cause, attack artifacts, fixed version, or detection signatures. Validation should remain non-destructive and vendor-guided.
Mitigation direction
Identify all deployments of the affected Oracle product and confirm their exact versions.
Review and apply Oracle's July 2026 Critical Patch Update guidance for affected systems.
Restrict HTTP access to trusted networks and authorized users until vendor remediation is complete.
Minimize privileges and disable unnecessary low-privileged accounts with access to the service.
Monitor affected systems and connected products for suspicious access or unauthorized changes.
Validation and detection
Verify whether Oracle Commerce Guided Search or Experience Manager 11.4.0 is deployed.
Map HTTP reachability, authentication paths, and low-privileged accounts for each deployment.
Confirm the Oracle-recommended remediation is installed on every affected instance.
Review HTTP, authentication, and administrative logs for unusual low-privileged activity.
Validate that low-privileged users cannot perform unauthorized administrative actions after remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-269: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-269 · source CWE mapping
Improper Privilege Management
Improper Privilege Management represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
Missing Authentication for Critical Function represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.