Sceawere
Vulnerability Detail
CVE-2026-71020UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Endeca Application Controller Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-08-18T21:18:01.447Z",
"pubdate": "2026-08-18T21:18:01.447Z",
"executiveSummary": "An easily exploitable security vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. The vulnerability impacts supported version 11.4.0 of the software. It allows a low-privileged attacker with network access via HTTP to execute malicious payloads, resulting in significant security implications across the environment due to a scope change. Successful exploitation requires human interaction from an individual other than the attacker. The potential business and operational impact includes unauthorized critical access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, as well as unauthorized update, insert, or delete capabilities against a subset of accessible data. The vulnerability carries a CVSS 3.1 Base Score of 7.6 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N, highlighting severe confidentiality compromise and moderate integrity compromise driven by network vector accessibility and low privilege requirements.",
"technicalDetails": "The security vulnerability resides within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw is exposed via the HTTP protocol, allowing remote network-based exploitation vectors to interact with the vulnerable application interface. The vulnerability demands low privileges from an authenticated attacker, meaning the malicious actor must possess a valid, low-tier user account within the system to initiate the attack sequence. Furthermore, successful exploitation is contingent upon human interaction, typically requiring a victim—such as a higher-privileged user or administrator—to interact with maliciously crafted content or a manipulated interface element supplied by the attacker. Because the vulnerability involves a scope change (S:C), a successful attack breaches the security boundary of the vulnerable component, enabling the adversary to impact resources and data structures outside the immediate administrative or functional domain of the Endeca Application Controller. The attack flow initiates when the low-privileged attacker crafts a malicious HTTP-based payload targeting the Endeca Application Controller component. The attacker then induces the required human interaction, compelling another user to process or load the malicious request within their authenticated session context. Upon execution, the payload leverages the application's trust relationship and processing logic to bypass authorization controls. This results in severe post-exploitation consequences, specifically granting the attacker unauthorized high-level access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, alongside unauthorized update, insert, or delete access to a subset of the application data."
}