Sceawere
Vulnerability Detail
CVE-2026-71018UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search EAC Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-18T21:18:01.217Z",
"pubdate": "2026-08-18T21:18:01.217Z",
"executiveSummary": "An unauthenticated vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. The vulnerability impacts version 11.4.0 and is remotely accessible via HTTP over the network, allowing an unauthenticated attacker to compromise the targeted system without holding prior credentials or privileges.\nSuccessful exploitation of this vulnerability requires human interaction from an individual other than the attacker, typically manifesting as a client-side interaction vector such as Cross-Site Scripting (XSS) or a similar browser-based flaw that exhibits a scope change (S:C). While the entry point resides within Oracle Commerce Guided Search / Oracle Commerce Experience Manager, successful attacks can propagate and significantly impact additional integrated or peripheral products.\nThe risk implications are severe due to the resulting confidentiality and integrity impacts. An attacker who successfully leverages this security flaw can gain unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Furthermore, the vulnerability permits unauthorized update, insert, or delete access to a subset of the accessible data within the application.\nGiven the CVSS 3.1 Base Score of 8.2 and the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N), organizations running version 11.4.0 must treat this as a high-priority risk, as it combines low attack complexity and network accessibility with high confidentiality degradation and cross-scope compromise potential.",
"technicalDetails": "The vulnerability exists within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insecure handling of HTTP requests, lacking proper input sanitization, output encoding, or request validation mechanisms, which allows malicious payloads to be processed and rendered within the context of a user session.\nThe attack vector is network-based (AV:N), allowing remote adversaries to interact with the target via standard HTTP protocols without requiring any prior authentication (PR:N) or specialized privileges. The attack complexity is rated as low (AC:L), meaning the conditions required to mount a successful exploit are straightforward and reliably reproducible once the target surface is identified.\nExploitation requires user interaction (UI:R), necessitating that a victimized user—other than the attacker—perform an action, such as clicking a malicious link or interacting with crafted web content delivered via HTTP. Upon processing the malicious request, the vulnerability triggers a scope change (S:C), allowing the attack context to cross security boundaries and potentially compromise secondary components or additional products integrated within the environment.\nThe attack flow proceeds as follows: First, the unauthenticated attacker crafts a specialized HTTP payload targeting the Endeca Application Controller interface. Second, the attacker induces a targeted user to interact with the crafted request via social engineering or reflected mechanisms. Third, the application processes the input unsafely, executing the attacker-supplied payload within the user's browser or session context. Finally, due to the scope change and elevated permissions of the affected application logic, the exploit achieves unauthorized read access to critical or total application data (C:H) and unauthorized modification, insertion, or deletion capabilities against targeted data subsets (I:L)."
}