Sceawere

Vulnerability Detail

CVE-2026-61161Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Endeca Remote Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:47.687Z",
  "pubdate": "2026-07-21T22:18:47.687Z",
  "executiveSummary": "A critical security vulnerability exists within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically impacting the Endeca Application Controller component in version 11.4.0.\nThis vulnerability is classified as a high-severity flaw with a CVSS 3.1 base score of 9.8, indicating that it poses a significant threat to the confidentiality, integrity, and availability of the affected system.\nThe vulnerability allows an unauthenticated remote attacker to gain complete unauthorized control over the Oracle Commerce Guided Search / Oracle Commerce Experience Manager platform.\nExploitation does not require valid user credentials or user interaction, making it highly accessible to external threat actors with network access via HTTP.\nGiven the nature of the exploit, successful compromise results in a full system takeover, potentially allowing attackers to exfiltrate sensitive commerce data, modify application configurations, or disrupt critical business services.\nOrganizations using version 11.4.0 are at immediate risk, and the primary risk implication is a total breach of the application environment.",
  "technicalDetails": "The vulnerability resides within the Endeca Application Controller component, which is responsible for managing the lifecycle and orchestration of Oracle Commerce Guided Search environments.\nThe flaw stems from an insecure implementation in the handling of network requests transmitted over the HTTP protocol. By failing to properly enforce authentication mechanisms or input validation controls for critical management functions, the Endeca Application Controller exposes an attack surface that allows unauthenticated remote execution of unauthorized commands.\nThe attack vector is characterized by its simplicity: the attacker transmits a crafted HTTP request directly to the vulnerable component. Because the vulnerability requires no prior authentication (PR:N) and no user interaction (UI:N) with a low attack complexity (AC:L), an attacker can reliably trigger the exploit over a standard network connection.\nStep-by-step, the attack flow begins with the reconnaissance of the network to identify reachable Endeca Application Controller endpoints. Once located, the attacker sends a malicious HTTP request designed to interact with the internal controller logic. Because the component lacks robust security boundaries or session verification, the request is processed with high privileges, effectively bypassing the expected authentication gateway.\nUpon successful processing of the payload, the attacker can leverage the controller's administrative functions to execute arbitrary commands or manipulate system configurations. This effectively transitions the attacker from an unauthenticated network visitor to a system administrator. The post-exploitation impact includes the ability to modify, delete, or exfiltrate any data residing within the Oracle Commerce environment. Furthermore, the attacker gains the ability to manipulate the runtime state of the application, potentially leading to persistent backdoors or the deployment of secondary malicious payloads.\nThe vulnerability affects version 11.4.0 of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that the scope remains within the single affected application, but the impact level on the primary security triad is total, leading to a complete compromise of the system."
}
CVE-2026-61161: Oracle Commerce Endeca Remote Takeover (CRITICAL Severity, CVSS: 9.8) - Sceawere