Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Commerce Guided Search / Oracle Commerce Experience Manager’s Endeca Application Controller component allows an unauthenticated attacker to retrieve critical data via an HTTP request, resulting in full exposure of all data available through the service. The vulnerability allows bypassing access controls, enabling unauthorized access. Based on the description, it is inferred that the attack requires only network connectivity to the HTTP interface and does not rely on user credentials. The compromise impacts confidentiality by revealing sensitive information that can be used for further malicious activities. This flaw aligns with CWE-284.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. The advisory notes that attacks may also compromise additional connected Oracle Commerce components, potentially expanding the impact beyond the initial product.

Risk and Exploitability

The vulnerability receives a CVSS 3.1 base score of 8.6, classifying it as high severity. The EPSS score of < 1% indicates a low probability of exploitation, yet the unauthenticated nature and reliance on HTTP access could lead opportunistic attackers to target it. This flaw aligns with CWE-284 and results in a scope change, meaning that a successful breach could extend to other services under the same application umbrella. The product is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation depends on the public availability of the vulnerability details.

Generated by OpenCVE AI on August 21, 2026 at 02:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the Oracle patch addressing CVE-2026-70996, as outlined in Oracle’s August 2026 security alert.
  • Restrict direct HTTP access to the Oracle Commerce Guided Search component to trusted IP ranges or suspend the service from public networks until patched.
  • Monitor application logs for abnormal access patterns and consider enforcing authentication or additional authorization checks as a temporary containment measure.

Generated by OpenCVE AI on August 21, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Fri, 21 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Disclosure via Oracle Commerce Guided Search

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attack Enables Full Data Disclosure in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Wed, 19 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attack Enables Full Data Disclosure in Oracle Commerce Guided Search 11.4.0
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:16:57.676Z

Reserved: 2026-08-04T22:06:34.610Z

Link: CVE-2026-70996

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:58.657

Modified: 2026-08-24T16:40:07.610

Link: CVE-2026-70996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:00:04Z

Weaknesses