Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privilege escalation flaw exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An attacker who can log on to the underlying host can exploit this flaw to create, delete, or modify application data, and to read all data accessible through the application. This jeopardizes the confidentiality and integrity of critical business information without requiring any user interaction.

Affected Systems

The affected vendor is Oracle Corporation, specifically the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product version 11.4.0. No other versions are listed as vulnerable in the current advisory.

Risk and Exploitability

According to the advisory the CVSS v3.1 base score is 7.1, with a local, low‑privilege attack vector and no user interaction, indicating a significant risk to confidentiality and integrity. The EPSS indicates under 1 % exploit probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker possess valid credentials or otherwise be able to log on to the host that runs the application, but no elevated privilege or network access is required.

Generated by OpenCVE AI on August 4, 2026 at 01:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU July 2026 advisory for Oracle Commerce Guided Search / Oracle Commerce Experience Manager or upgrade to a newer version.
  • Restrict local account access on the host that runs the application, ensuring only necessary privileged accounts exist and following the principle of least privilege.
  • Enforce application‑level access controls and enable auditing for data creation, deletion, or modification actions to detect and prevent unauthorized activity.
  • Consider segmenting the network to limit host exposure so that only authorized services or administrators can reach the application server.

Generated by OpenCVE AI on August 4, 2026 at 01:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Commerce Endeca Application Controller Allows Data Modification and Disclosure

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Commerce Endeca Application Controller Allows Data Modification and Disclosure

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Guided Search And Experience Manager
Vendors & Products Oracle commerce Guided Search And Experience Manager

Mon, 27 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Unauthorized Data Modification in Oracle Commerce Guided Search
Weaknesses CWE-862

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Unauthorized Data Modification in Oracle Commerce Guided Search
Weaknesses CWE-862

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager Commerce Guided Search And Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:27:06.738Z

Reserved: 2026-07-08T15:52:20.738Z

Link: CVE-2026-61162

cve-icon Vulnrichment

Updated: 2026-07-23T18:27:03.388Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses