Junglewise Threat Intelligence

CVE-2026-71015: Oracle Commerce Guided Search authentication bypass

CVE-2026-71015 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager (components of Oracle's e-commerce platform) contain an authentication bypass vulnerability in the Endeca Application Controller. An unauthenticated attacker with network access can exploit this flaw to read, create, modify, or delete critical business data stored in the system, potentially exposing customer information, product catalogs, and transaction records.

Technical details

This is an authentication bypass vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The flaw is easily exploitable via network-accessible HTTP interfaces without requiring authentication or user interaction. An unauthenticated attacker can achieve unauthorized access to critical data, including creation, deletion, or modification of records, and complete read access to all system data. Affected version is 11.4.0. Patch availability has not been confirmed from the available advisory text.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed: Vulnerability published in Oracle Critical Patch Update

References

Related threats