Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) permits an unauthenticated network attacker to perform unauthorized updates, inserts, deletes, and reads of data exposed by the application. The flaw resides in the Endeca Application Controller component and requires human interaction from a user other than the attacker to complete the attack sequence.

Affected Systems

Affected products are Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically version 11.4.0. The vulnerability is listed in the vendor advisory and no other versions or related products are currently identified as impacted.

Risk and Exploitability

The CVSS 3.1 base score is 6.1, indicating medium severity with confidentiality and integrity impacts. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based via HTTP, unauthenticated, though human interaction from a person other than the attacker is required. Once the initial exploit is successful, the attacker can alter or delete data and gain read access to sensitive information, presenting a moderate but tangible risk.

Generated by OpenCVE AI on August 20, 2026 at 19:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or upgrade Oracle Commerce Guided Search / Oracle Commerce Experience Manager to a non‑vulnerable version as released by Oracle.
  • Restrict external HTTP access the Endeca Application Controller by implementing firewalls or IP whitelisting so that only trusted internal hosts can reach the component.
  • Enforce least‑privilege access controls on data modification and retrieval interfaces, ensuring that only authorized roles can perform update or delete actions.

Generated by OpenCVE AI on August 20, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Commerce Guided Search 11.4.0

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Commerce Guided Search

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Commerce Guided Search

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Commerce Guided Search via HTTP
Weaknesses CWE-284

Wed, 19 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Commerce Guided Search via HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:06:37.166Z

Reserved: 2026-08-04T22:06:34.612Z

Link: CVE-2026-71025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:02.037

Modified: 2026-08-31T12:24:17.723

Link: CVE-2026-71025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:45:03Z

Weaknesses