Sceawere

Vulnerability Detail

CVE-2026-71027UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Endeca Application Controller Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-08-18T21:18:02.270Z",
  "pubdate": "2026-08-18T21:18:02.270Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically residing in the Endeca Application Controller component. The affected supported version is 11.4.0. This security flaw enables a low-privileged attacker with network access via HTTP to compromise the targeted system.\nSuccessful exploitation of this vulnerability necessitates human interaction from an individual other than the attacker. Due to a scope change characteristic, successful attacks can significantly impact additional products beyond the immediate Oracle Commerce Guided Search / Oracle Commerce Experience Manager boundary.\nThe risk implications are severe, yielding a CVSS 3.1 Base Score of 7.6. The attack vector is network-based (AV:N), with low attack complexity (AC:L), low privileges required (PR:L), and required user interaction (UI:R). The impact includes complete unauthorized access to critical data and all accessible data within the application (C:H), alongside unauthorized update, insertion, or deletion capabilities for a subset of accessible data (I:L), while availability remains unaffected (A:N).",
  "technicalDetails": "The vulnerability manifests within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The architecture exposes functional interfaces over HTTP that process untrusted inputs or facilitate operations reachable by network-authenticated users holding low privileges.\nThe attack vector relies on network accessibility (AV:N) via the HTTP protocol. An authenticated attacker with low privileges (PR:L) can craft malicious requests targeting the vulnerable component. However, the attack mechanism strictly requires human interaction (UI:R) from a third party, such as an administrator or another user, to successfully trigger the execution flow or state transition necessary to compromise the application.\nDue to the scope change (S:C) metric designation, the vulnerability allows an attacker interacting with the Endeca Application Controller to transcend the security boundaries of the primary product, thereby exerting significant security impacts on secondary or additional integrated products within the environment.\nUpon successful exploitation, the payload behavior and post-exploitation impact allow the adversary to bypass authorization controls. This results in unauthorized high-level or complete confidentiality compromise (C:H) regarding critical data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Furthermore, the attacker gains unauthorized integrity manipulation capabilities (I:L), permitting the update, insertion, or deletion of a subset of the application's accessible data. Availability is not impacted during this attack chain (A:N)."
}
CVE-2026-71027: Oracle Commerce Endeca Application Controller Vulnerability (HIGH Severity, CVSS: 7.6) - Sceawere