Sceawere
Vulnerability Detail
CVE-2026-71028UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Endeca Application Controller Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-18T21:18:02.383Z",
"pubdate": "2026-08-18T21:18:02.383Z",
"executiveSummary": "A security vulnerability has been identified within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically residing in the Endeca Application Controller component. The vulnerability impacts version 11.4.0 of the software.\nThis security flaw is classified as easily exploitable, requiring a low-privileged attacker to possess valid local logon access to the underlying infrastructure where the affected Oracle Commerce Guided Search / Oracle Commerce Experience Manager instance executes.\nSuccessful exploitation of this vulnerability grants the adversary the capability to achieve a complete system takeover of the targeted Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployment.\nThe severity of this issue is reflected in its CVSS 3.1 Base Score of 7.8, with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating high impacts across confidentiality, integrity, and availability.\nOrganizations utilizing the affected software version face significant operational and security risks, as an authenticated local threat actor can leverage this weakness to completely compromise the integrity and confidentiality of the targeted commerce platform infrastructure.",
"technicalDetails": "The vulnerability exists within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient security controls or inadequate access restrictions within the component, allowing locally authenticated users to manipulate execution flows or escalate privileges.\nThe attack vector is strictly local (AV:L), meaning the adversary must already have established an interactive session or valid logon capability on the host operating system where the service executes. However, the attack complexity is rated as low (AC:L), and the required privileges are low (PR:L), indicating that standard user accounts possessing local infrastructure access can successfully execute the attack.\nUser interaction is not required (UI:N) for successful exploitation, and the security scope remains unchanged (S:U). The attack flow begins with the low-privileged attacker leveraging their local infrastructure access to interact directly with the vulnerable Endeca Application Controller component.\nDue to the lack of proper validation or permission boundaries within the component, the attacker can supply specially crafted inputs or execute unauthorized administrative operations managed by the controller.\nPost-exploitation impact is severe, resulting in a full takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. This provides the attacker with high (H) confidentiality impact to read sensitive data, high (H) integrity impact to modify system configurations and application logic, and high (H) availability impact to disrupt or terminate service operations entirely."
}