Description
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows a local attacker with existing logon credentials to compromise the application. A successful exploitation permits the attacker to read or obtain all data accessible through the application, effectively breaching confidentiality. Based on the description, it is inferred that improper access control enables reading of protected data without proper authorization.

Affected Systems

Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0, are affected. No other versions or products were identified, and this applies only to installations where the Endeca Application Controller is present.

Risk and Exploitability

The vulnerability receives a CVSS base score of 5.5, indicating moderate severity, with local access required and low privileges sufficient for exploitation. EPSS indicates a very low exploitation probability (<1%), and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current evidence of widespread exploitation. The attack would need a user or process on the same host to interact with the application controller, but once achieved, the attacker can read critical data exposed by the application.

Generated by OpenCVE AI on August 20, 2026 at 18:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade for Oracle Commerce Guided Search / Oracle Commerce Experience Manager that addresses CVE-2026-71033.
  • Limit local network access to the servers running Oracle Commerce Guided Search by enforcing network segmentation, strict firewall rules, and role‑based access control to the underlying operating system.
  • Review and tighten permissions on Endeca Application Controller objects, ensuring that only privileged accounts can read protected data, and disable or remove any unnecessary accounts or services that provide local access.

Generated by OpenCVE AI on August 20, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle commerce Experience Manager
Oracle commerce Guided Search
CPEs cpe:2.3:a:oracle:commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle commerce Experience Manager
Oracle commerce Guided Search

Thu, 20 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Local Access Compromise in Oracle Commerce Guided Search

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability in Oracle Commerce Guided Search Allows Unauthorized Data Access
Weaknesses CWE-284

Wed, 19 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability in Oracle Commerce Guided Search Allows Unauthorized Data Access
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
CPEs cpe:2.3:a:oracle:commerce_guided_search_\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Guided Search \/ Oracle Commerce Experience Manager
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Experience Manager Commerce Guided Search Commerce Guided Search \/ Oracle Commerce Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:00:57.827Z

Reserved: 2026-08-04T22:06:34.613Z

Link: CVE-2026-71033

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:21.232Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:02.957

Modified: 2026-08-31T12:16:56.400

Link: CVE-2026-71033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:45:03Z

Weaknesses