Executive brief
Oracle Commerce Experience Manager, a tool used by businesses to manage and deliver personalized search and shopping experiences, contains a security vulnerability. An attacker with low-level user credentials can access the system over the network to view, modify, or delete certain business data. This could lead to unauthorized changes to product listings or the exposure of internal search configuration data.
Technical details
A vulnerability in the Experience Manager component of Oracle Commerce Guided Search (formerly Endeca) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read, insert, update, or delete a subset of data accessible to the Experience Manager. The vulnerability affects version 11.4.0 and is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Commerce Guided Search / Experience Manager 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory