Sceawere

Vulnerability Detail

CVE-2026-71021UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search EAC Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-08-18T21:18:01.567Z",
  "pubdate": "2026-08-18T21:18:01.567Z",
  "executiveSummary": "A vulnerability has been identified in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. This security flaw affects version 11.4.0 of the software.\nThe vulnerability allows a low-privileged attacker with network access via HTTP to compromise the affected product. Successful exploitation requires human interaction from an individual other than the attacker. A successful attack can result in a scope change, significantly impacting additional products beyond the primary target.\nThe primary security impacts include unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager, alongside unauthorized update, insert, or delete access to a subset of the accessible data. The CVSS 3.1 base score is 7.6, reflecting severe confidentiality and integrity impacts with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N.",
  "technicalDetails": "The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0.\nThe attack vector is network-based (AV:N), allowing remote threat actors to reach the vulnerable interface via the HTTP protocol. Exploitation features low attack complexity (AC:L), meaning the conditions required for a successful attack are straightforward without demanding complex environmental configurations.\nAn attacker must authenticate with low privileges (PR:L) to initiate the attack sequence, but successful exploitation explicitly requires human interaction (UI:R) from a third party, such as an administrator or user interacting with the application.\nThe security flaw involves a scope change (S:C), indicating that successful exploitation breaks security boundaries, allowing the attacker to impact components or products outside the immediate security context of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.\nThe step-by-step attack flow involves the low-privileged attacker crafting a malicious request or payload delivered over HTTP to the Endeca Application Controller. Through requisite user interaction—such as a victim navigating a crafted link or interacting with manipulated application states—the payload executes within the application context. Because of the scope change attribute, the attack propagates or escalates privileges across interconnected systems.\nThe post-exploitation impact yields severe consequences for data security. The attacker achieves high confidentiality (C:H) impact, leading to unauthorized access to critical or complete data stores managed by the affected products. Additionally, the attacker gains low integrity (I:L) impact, permitting unauthorized modifications, insertions, or deletions of specific data subsets within the system. Availability is unaffected (A:N)."
}
CVE-2026-71021: Oracle Commerce Guided Search EAC Vulnerability (HIGH Severity, CVSS: 7.6) - Sceawere