A vulnerability described as critical has been identified in Oracle Commerce Guided Search and Commerce Experience Manager 11.4.0. This vulnerability affects unknown code of the component Content Acquisition System. The manipulation results in improper privilege management.

This vulnerability is cataloged as CVE-2026-61146. The attack may be launched remotely. There is no exploit available.