Sceawere

Vulnerability Detail

CVE-2026-70994UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search EAC Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:17:58.423Z",
  "pubdate": "2026-08-18T21:17:58.423Z",
  "executiveSummary": "An unauthenticated remote vulnerability affecting the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product poses significant security risks to enterprise environments.\nSpecifically localized within the Endeca Application Controller component, this flaw enables malicious actors with network connectivity via HTTP to compromise the target application without requiring prior authentication, user interaction, or elevated privileges.\nSuccessful exploitation of this security issue grants attackers unauthorized access to highly sensitive, critical data contained within the system, alongside the capability to trigger a complete denial of service through repeated application crashes or system hangs.\nWith a CVSS 3.1 Base Score of 9.1 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H, the vulnerability highlights severe exposure regarding confidentiality and availability.\nThe low attack complexity and lack of required privileges mean that threat actors can scale exploitation efforts rapidly across exposed network perimeters.\nOrganizations utilizing the affected software version must prioritize risk management to prevent unauthorized data exposure and operational outages.",
  "technicalDetails": "The vulnerability resides within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.\nThe root cause stems from insufficient validation and access controls within the exposed HTTP-based management or control interfaces of the Endeca Application Controller.\nBecause the interface lacks authentication and authorization checks, any remote attacker with network access to the HTTP service can interact directly with vulnerable functions.\nThe attack flow begins when an unauthenticated client transmits specially crafted HTTP requests targeting the vulnerable Endeca Application Controller endpoints.\nDue to the absence of privilege requirements (PR:N) and low attack complexity (AC:L), the application processes the malicious payload without validating the identity or permissions of the source.\nUpon processing, the payload exploits underlying flaws in data handling, allowing the attacker to bypass confidentiality boundaries and read critical proprietary data accessible to the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment.\nSimultaneously, alternative or subsequent malicious payloads can exhaust system resources, corrupt internal states, or trigger unhandled exceptions within the vulnerable component.\nThis leads to an immediate hang or a frequently repeatable crash, resulting in a complete denial of service (DoS) for the application.\nThe post-exploitation impact spans severe data exfiltration regarding sensitive business intelligence, catalogs, or user data, coupled with a total disruption of service availability, impairing e-commerce operations until manual administrative intervention or service recovery is performed."
}
CVE-2026-70994: Oracle Commerce Guided Search EAC Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere