Sceawere
Vulnerability Detail
CVE-2026-71015UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search EAC Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-08-18T21:18:00.877Z",
"pubdate": "2026-08-18T21:18:00.877Z",
"executiveSummary": "An unauthenticated remote vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. The vulnerability is easily exploitable over the network via the HTTP protocol without requiring any user interaction or prior authentication privileges. Successful exploitation grants an attacker unauthorized read, creation, modification, and deletion access to critical data and all accessible information within the affected product. The resulting impact compromises both data confidentiality and data integrity, yielding a critical CVSS 3.1 base score of 9.1 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. This poses severe risk implications for organizations utilizing the software, as external threat actors can manipulate or exfiltrate sensitive application data remotely.",
"technicalDetails": "The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from improper access control enforcement or missing authentication checks within the HTTP request handling pathways exposed by the application controller. Because the attack vector is network-based (AV:N) and complexity is low (AC:L), an unauthenticated attacker (PR:N) with network connectivity can directly target the exposed HTTP interfaces without needing valid user credentials or user interaction (UI:N).\nDuring the attack flow, an adversary crafts malicious HTTP requests targeted at vulnerable endpoints managed by the Endeca Application Controller. Due to the absence of robust access controls and input validation routines, the application processes these unauthenticated requests as legitimate operational commands. This allows the remote actor to bypass security boundaries entirely.\nThe post-exploitation impact enables the attacker to execute unauthorized data manipulation operations. Specifically, the attacker achieves unauthorized creation, deletion, and modification capabilities over critical data repositories, alongside unconstrained access to read all accessible data within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager environment. The scope remains unchanged (S:U), but the direct degradation of confidentiality (C:H) and integrity (I:H) severely undermines the security posture of the host system while availability (A:N) remains unaffected."
}