A vulnerability classified as critical has been found in Oracle Commerce Experience Manager and Commerce Guided Search 11.4.0. This issue affects some unknown processing of the component Experience Manager. This manipulation causes privilege escalation.

This vulnerability is registered as CVE-2026-61148. Remote exploitation of the attack is possible. No exploit is available.