Sceawere

Vulnerability Detail

CVE-2026-71026UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Guided Search EAC Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:18:02.160Z",
  "pubdate": "2026-08-18T21:18:02.160Z",
  "executiveSummary": "An unauthenticated remote vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. The vulnerability is easily exploitable over the network via HTTP without requiring any user interaction or privileges. Successful exploitation grants unauthorized actors the capability to read, create, delete, or modify critical data and all accessible data within the affected system. With a CVSS 3.1 Base Score of 9.1 and high impacts to both confidentiality and integrity, this flaw poses severe risk implications to enterprise environments utilizing the vulnerable software. The attack surface is exposed directly through network protocols, enabling malicious entities to compromise system data integrity and confidentiality entirely without authentication.",
  "technicalDetails": "The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient access controls and input validation mechanisms within the network-exposed management interfaces. The attack flow begins when an unauthenticated attacker leverages network access via HTTP to interact directly with the vulnerable Endeca Application Controller component. Because the affected system fails to enforce proper authentication and authorization checks, the attacker can transmit malicious HTTP requests across the network without supplying valid credentials or interacting with a local user.\nThe exploitation method relies on the public exposure of the HTTP service, allowing the arbitrary execution of administrative or data-handling operations intended only for authorized entities. Upon receiving the crafted payload, the vulnerable Endeca Application Controller processes the request and executes unauthorized data manipulation or retrieval routines. The post-exploitation impact includes complete compromise of confidentiality and integrity, as attackers achieve unauthorized read access to critical data along with the ability to create, modify, or delete sensitive records across the entire Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployment. The vector is classified as network-accessible (AV:N), with low attack complexity (AC:L), requiring no privileges (PR:N) and no user interaction (UI:N), resulting in a scope-unchanged (S:U) state with high impacts to confidentiality (C:H) and integrity (I:H)."
}
CVE-2026-71026: Oracle Commerce Guided Search EAC Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere