Junglewise Threat Intelligence

CVE-2026-70998: Oracle Commerce Guided Search remote unauthenticated data access

CVE-2026-70998 · Severity: critical · CVSS 9.3 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search is a component that powers product search and filtering functionality in e-commerce platforms. An unauthenticated attacker can remotely exploit this vulnerability via the network to read, modify, and delete sensitive customer and business data, potentially exposing personal information and allowing unauthorized transactions or inventory changes.

Technical details

The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search and Commerce Experience Manager. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no authentication, low complexity, and no user interaction. The vulnerability allows attackers to read confidential data accessible to the application and to modify or delete some application data. The scope change indicates that impacts extend beyond the vulnerable component to other Oracle Commerce products.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats