Sceawere

Vulnerability Detail

CVE-2026-71031UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Endeca Application Controller Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-18T21:18:02.723Z",
  "pubdate": "2026-08-18T21:18:02.723Z",
  "executiveSummary": "A security vulnerability has been identified within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically residing in the Endeca Application Controller component. This remotely exploitable vulnerability poses a moderate risk to confidentiality and integrity across affected enterprise environments. The flaw allows an unauthenticated threat actor with network access via HTTP to compromise the target system, provided that the attack vector incorporates successful human interaction from a third party. Although the vulnerable code execution is contained within the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product boundary, successful exploitation introduces a scope change, meaning that the impact can propagate to significantly affect additional integrated or collateral products. Upon successful exploitation, unauthorized adversaries can achieve unauthorized read access to a subset of accessible data, as well as unauthorized update, insert, or delete capabilities against specific data assets managed by the application. The severity of this vulnerability is quantified by a CVSS 3.1 Base Score of 6.1, driven by network vector exposure, low attack complexity, lack of required attacker privileges, and necessary user interaction combined with a changed security scope.",
  "technicalDetails": "The vulnerability exists within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The attack vector is exposed over the network utilizing the HTTP protocol, allowing unauthenticated threat actors to initiate interactions without holding prior credentials or pre-existing system privileges. The exploitation process requires low attack complexity but is contingent upon human interaction from an individual other than the attacker, typically manifesting as a client-side execution vector such as a cross-site scripting or induced browser-based state manipulation where a victim interacts with a malicious payload or crafted link. Because the vulnerability exhibits a scope change (S:C), the privileges or trust relationship abused within the Endeca Application Controller component bypass security boundaries to impact secondary systems or collateral products governed by the overarching architecture. Upon successful delivery of the attack payload via HTTP, the underlying mechanism processes untrusted input or state improperly, resulting in compromised data integrity and confidentiality. The resulting post-exploitation impact grants the attacker unauthorized read access to a subset of accessible data alongside unauthorized update, insertion, and deletion permissions against targeted data subsets within the scope of the application architecture. The absence of authentication and privilege requirements lowers the barrier for external actors, while the necessity of user interaction serves as the primary gating condition for successful payload execution."
}
CVE-2026-71031: Oracle Commerce Endeca Application Controller Vulnerability (MEDIUM Severity, CVSS: 6.1) - Sceawere