A vulnerability marked as critical has been reported in Oracle Commerce Guided Search and Commerce Experience Manager 11.4.0. This affects an unknown part of the component Content Acquisition System. The manipulation leads to Remote Code Execution.

This vulnerability is listed as CVE-2026-61145. The attack may be initiated remotely. There is no available exploit.