Junglewise Threat Intelligence

CVE-2026-61162: Oracle Commerce Guided Search data compromise in Endeca Application Controller

CVE-2026-61162 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Commerce Guided Search and Experience Manager, tools used by businesses to manage site search and customer experiences. An attacker who already has basic access to the underlying server can exploit this flaw to gain full control over the application's data. This could lead to the unauthorized viewing, modification, or deletion of sensitive business information and customer-facing content.

Technical details

A vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) allows a low-privileged attacker with local logon access to the hosting infrastructure to compromise the application. The exploit is characterized as 'easily exploitable' and does not require user interaction. Successful exploitation grants the attacker unauthorized access to read, create, delete, or modify all data accessible to the application. The vulnerability is tracked as CVE-2026-61162 with a CVSS 3.1 base score of 7.1, reflecting high impacts on confidentiality and integrity but no direct impact on availability.

Affected products

  • Oracle Commerce Guided Search / Experience Manager 11.4.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update advisory.
  • 2026-07-21: disclosed: CVE-2026-61162 was published to the NVD.

References

Related threats