Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation can lead to full takeover of the application, providing the attacker with complete control. The weakness is rated as high severity with a CVSS 3.1 base score of 9.8, indicating complete loss of confidentiality, integrity, and availability.

Affected Systems

Oracle Corporation – Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0 are impacted. No other versions or products are identified as vulnerable in the current advisory.

Risk and Exploitability

The vulnerability is remotely exploitable over standard HTTP traffic without requiring authentication or user interaction, while the EPSS score is < 1%, and the issue is not listed in CISA KEV. The high CVSS score reflects the potential for a successful attack, and organizations should treat this as an urgent threat even though no public exploit has been reported yet. The attack path requires only network reachability to the application, making the risk low‑if not mitigated but potentially catastrophic if successful.

Generated by OpenCVE AI on August 19, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a version that eliminates the flaw.
  • If an immediate patch is unavailable, block external HTTP access to the Oracle Commerce Guided Search / Experience Manager instance, allowing only trusted internal communications.
  • Monitor application and network logs for indications of exploitation attempts.

Generated by OpenCVE AI on August 19, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title High Severity Remote Exploit in Oracle Commerce Guided Search 11.4.0

Wed, 19 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title High Severity Remote Exploit in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:17:10.173Z

Reserved: 2026-08-04T22:06:34.610Z

Link: CVE-2026-70995

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:58.540

Modified: 2026-08-24T16:32:49.320

Link: CVE-2026-70995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T22:30:05Z

Weaknesses