Executive brief
Oracle Commerce Guided Search and Experience Manager, which power e-commerce search and personalization for online retailers, contain an authentication bypass vulnerability in their core application controller. An unauthenticated attacker can remotely exploit this flaw over the network to read, modify, or delete critical business data, including sensitive customer and product information, without any credentials or user interaction.
Technical details
The vulnerability is an unauthenticated remote code execution or data access flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager 11.4.0. The vulnerability allows an unauthenticated attacker with network access via HTTP to bypass authentication controls and gain unauthorized access to critical data. Successful exploitation results in both confidentiality and integrity impacts, enabling unauthorized read, modification, and deletion of all accessible data within the system. The attack is easily exploitable with no prerequisites (no authentication required, low complexity, no user interaction). Patches are expected from Oracle as part of their standard security update cycle.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed