Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Commerce Guided Search and Oracle Commerce Experience Manager incorporate a flaw in the Endeca Application Controller that, when accessed over HTTP without authentication, allows an attacker to directly compromise the application. The issue results from improper access control and missing authentication mechanisms, classified as CWE-284 and CWE-306. Successful exploitation can lead to full takeover of the application, compromising confidentiality, integrity, and availability.

Affected Systems

The affected vendors are Oracle Corporation. The product line impacted is Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically the 11.4.0 release. No other versions or products are noted as affected in the data.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 9.8, indicating critical severity and the potential for complete control over the system. The EPSS score is reported as less than 1 %, implying a low but non‑zero likelihood of exploitation in the current period. The issue is not listed in CISA's KEV catalog. Attackers can exploit the flaw by making unauthenticated HTTP requests to the exposed Endeca Application Controller endpoint, which does not enforce authentication or access control, enabling remote takeover of the application.

Generated by OpenCVE AI on August 2, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch provided in the July 2026 CPU, which resolves the Endeca Application Controller flaw.
  • If a patch is not yet applied, restrict inbound HTTP traffic to the Commerce instance by blocking all traffic except from trusted IP ranges or by moving the instance behind a reverse proxy that enforces authentication.
  • Disable any anonymous or default access to the application endpoints to ensure that only authenticated users can reach the controller.

Generated by OpenCVE AI on August 2, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Commerce Guided Search / Experience Manager

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Remote Code Execution via HTTP
Weaknesses CWE-94

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search And Experience Manager
Vendors & Products Oracle commerce Guided Search And Experience Manager

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Remote Code Execution via HTTP
Weaknesses CWE-94

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager Commerce Guided Search And Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:27:56.363Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61161

cve-icon Vulnrichment

Updated: 2026-07-23T18:27:52.927Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:45:06Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function