Sceawere

Vulnerability Detail

CVE-2026-71017UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search EAC Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:18:01.103Z",
  "pubdate": "2026-08-18T21:18:01.103Z",
  "executiveSummary": "A remotely exploitable security vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. This vulnerability presents significant risk implications for organizations utilizing the affected software by potentially compromising sensitive business data and service availability. An unauthenticated remote attacker with network access via the HTTP protocol can leverage this flaw to compromise the target application. Successful exploitation requires high attack complexity but yields severe operational consequences, including unauthorized access to critical data and the capability to induce a partial denial of service condition. The base severity of this security issue is quantified by a CVSS 3.1 score of 6.5, with high confidentiality impact and low availability impact, operating under a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L. Mitigation requires careful adherence to vendor advisories and applying appropriate network segmentation or access controls to limit exposure of the vulnerable component to untrusted networks.",
  "technicalDetails": "The vulnerability resides within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient validation or access restriction handling within the component when processing incoming HTTP requests. The affected attack vector is network-based (AV:N), allowing any unauthenticated remote entity (PR:N, UI:N) with HTTP connectivity to interact with the vulnerable interface. Although exploitation requires high attack complexity (AC:H)—implying that an attacker must meet specific precondition criteria, race conditions, or precise timing parameters—successful execution does not require prior privileges or user interaction. The attack flow initiates when a malicious or malformed HTTP request is transmitted across the network to the exposed Endeca Application Controller service. Upon receipt, the vulnerable component improperly handles the input or state transition, allowing the adversary to bypass access controls. This unauthorized interaction leads directly to two distinct functional impacts. First, it enables unauthorized read access to critical data, violating the confidentiality boundary (C:H) by exposing sensitive information accessible to the Oracle Commerce Guided Search / Oracle Commerce Experience Manager ecosystem. Second, it disrupts normal service operations, resulting in a partial denial of service (A:L) that degrades application performance or availability. The scope remains unchanged (S:U), confining the direct impact to the vulnerable component itself without explicitly escalating privileges to underlying host operating systems based solely on the provided vector."
}
CVE-2026-71017: Oracle Commerce Guided Search EAC Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere