Sceawere

Vulnerability Detail

CVE-2026-70998UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Endeca Application Controller Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-08-18T21:17:58.883Z",
  "pubdate": "2026-08-18T21:17:58.883Z",
  "executiveSummary": "A critical security vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. The vulnerability impacts the supported version 11.4.0. It represents a remotely exploitable flaw that can be leveraged by an unauthenticated attacker with network access via the HTTP protocol, requiring no user interaction or prior privileges to execute successful attacks.\nThe severity of the vulnerability is reflected in its CVSS 3.1 Base Score of 9.3, driven by significant impacts to confidentiality and integrity, along with a scope change (S:C) indicating that successful exploitation can extend its effects beyond the primary product to additional systems. Attack capabilities include unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, as well as unauthorized update, insert, or delete access to a subset of the accessible data.",
  "technicalDetails": "The vulnerability resides within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insecure handling of network-based requests processed by the application via HTTP. Because the vulnerability is exposed over the network (AV:N), an attacker does not require physical or local access to the target system.\nExploitation requires low attack complexity (AC:L), meaning the adversary does not need to overcome significant procedural hurdles to mount an attack. Furthermore, the vulnerability requires no privileges (PR:N) and no user interaction (UI:N), allowing unauthenticated remote threat actors to interact directly with the vulnerable Endeca Application Controller component.\nThe attack flow proceeds as follows: An unauthenticated attacker establishes a network connection to the target Oracle Commerce environment via HTTP. By submitting specially crafted requests targeting the Endeca Application Controller, the attacker bypasses existing security boundaries. Due to the scope change (S:C), the compromise is not strictly contained within the boundaries of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, potentially affecting additional integrated or ancillary products.\nPost-exploitation impacts are severe, leading to high confidentiality breaches (C:H) where critical or all accessible data can be read by the unauthorized actor. Additionally, the vulnerability grants low integrity impacts (I:L), permitting unauthorized modifications through data updates, insertions, or deletions within the accessible dataset. Availability remains unaffected (A:N)."
}
CVE-2026-70998: Oracle Commerce Endeca Application Controller Vulnerability (CRITICAL Severity, CVSS: 9.3) - Sceawere