Sceawere
Vulnerability Detail
CVE-2026-71023UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Guided Search Integrity Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:18:01.810Z",
"pubdate": "2026-08-18T21:18:01.810Z",
"executiveSummary": "A vulnerability exists within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. This security flaw allows unauthenticated remote attackers with network access via HTTP to interact with vulnerable endpoints and compromise the system.\nThe primary risk associated with this vulnerability is the potential for unauthorized data manipulation. Successful exploitation grants attackers the capability to perform unauthorized creation, deletion, or modification of critical data, as well as any other data accessible within the scope of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.\nThe affected supported product version is 11.4.0. According to the CVSS 3.1 metrics, the vulnerability yields a base score of 7.5, reflecting a high impact on data integrity without affecting confidentiality or availability. The attack vector is strictly network-based (AV:N), with low attack complexity (AC:L), requiring zero privileges (PR:N) and no user interaction (UI:N) under a scope-unchanged (S:U) security context. This enables automated or opportunistic exploitation by remote threat actors lacking prior system access.",
"technicalDetails": "The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient access controls and inadequate input validation or authorization enforcement mechanisms exposed via the HTTP interface.\nBecause the vulnerable component fails to authenticate incoming requests or properly validate whether the connecting entity possesses the authorization to invoke administrative or data-altering functions, an unauthenticated remote attacker can issue crafted HTTP requests directly to the service.\nThe attack flow proceeds as follows: First, the attacker establishes network connectivity over HTTP to the exposed Endeca Application Controller service. Second, leveraging the lack of pre-authentication requirements (PR:N) and low attack complexity (AC:L), the attacker transmits malicious payloads or control commands designed to manipulate backend application data. Third, the Endeca Application Controller processes the unauthenticated requests, executing state-changing operations against the underlying data repositories.\nThe post-exploitation impact is strictly concentrated on data integrity (CVSS:3.1/I:H). Attackers can execute unauthorized creation, deletion, and modification routines against critical application records and system-managed datasets. The vulnerability does not directly permit unauthorized data exfiltration (C:N) or cause denial of service conditions (A:N), but the degradation or destruction of data integrity presents severe operational risks to e-commerce operations managed by the affected platform."
}