Sceawere

Vulnerability Detail

CVE-2026-71033UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Endeca Application Controller Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Guided Search / Oracle Commerce Experience Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-18T21:18:02.957Z",
  "pubdate": "2026-08-18T21:18:02.957Z",
  "executiveSummary": "An unauthorized data access vulnerability affects the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically within the Endeca Application Controller component. The vulnerability impacts version 11.4.0 of the software. Successful exploitation of this security flaw allows a low-privileged attacker who has obtained local logon access to the underlying infrastructure to compromise the application and achieve unauthorized access to critical data or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The vulnerability presents a CVSS 3.1 Base Score of 5.5, with impacts strictly limited to confidentiality, resulting in no direct integrity or availability disruption. The attack vector is local (AV:L), requiring low privileges (PR:L) and no user interaction (UI:N), with a low attack complexity (AC:L). Risk implications involve the potential exposure of sensitive business data managed within the affected Oracle Commerce components. Because the vulnerability requires prior local logon access, mitigation efforts should heavily focus on restricting infrastructure access, enforcing strict local permission boundaries, and applying official vendor patches as supplied by Oracle.",
  "technicalDetails": "The vulnerability resides within the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The root cause stems from insufficient access controls, permission validation flaws, or insecure resource handling within the affected component executing on the host infrastructure. The network exposure of this vulnerability is strictly local (AV:L), meaning remote network exploitation is not feasible directly through this specific vector; an adversary must first establish a valid interactive or programmatic logon session on the host operating system where the Oracle Commerce architecture executes.\nExploitation requirements mandate that the attacker possesses low privileges (PR:L) within the local environment and requires zero user interaction (UI:N). Given the low attack complexity (AC:L), a threat actor who has provisioned or compromised a low-privileged local user account can systematically interact with the Endeca Application Controller component or its underlying execution context. The attack flow proceeds as follows: first, the low-privileged user authenticates locally to the target infrastructure hosting the Oracle Commerce deployment. Second, leveraging the inadequate privilege boundaries or weak access controls enforced by the Endeca Application Controller, the actor initiates unauthorized queries, commands, or file system interactions targeting the application's data repositories or operational states. Finally, the attacker bypasses intended authorization checks to read sensitive backend files, configuration stores, or business datasets managed by the software.\nThe post-exploitation impact is characterized by a severe breach of confidentiality (C:H). Because the vulnerability allows unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data, an attacker can harvest proprietary catalogs, customer information, or internal configuration parameters. The vulnerability does not allow for direct system compromise beyond data exposure, as integrity (I:N) and availability (A:N) metrics remain unaffected under CVSS 3.1 parameters. The scope (S:U) remains unchanged, indicating that the security scope does not extend beyond the vulnerable Oracle Commerce component's direct authorization domain."
}
CVE-2026-71033: Oracle Commerce Endeca Application Controller Vulnerability (MEDIUM Severity, CVSS: 5.5) - Sceawere