Executive brief
A critical vulnerability has been identified in Oracle Commerce Guided Search and Experience Manager, specifically within the Endeca Application Controller component. This software is used by businesses to manage site search and customer experiences. An unauthenticated attacker can remotely exploit this flaw over the network to gain full control of the system, potentially leading to the theft of sensitive data, service disruption, or unauthorized modification of the customer-facing commerce environment.
Technical details
A critical vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the application. A successful exploit results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Commerce Guided Search / Commerce Experience Manager 11.4.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.