Executive brief
Oracle Commerce Guided Search and Experience Manager are components used to power product discovery and search in e-commerce platforms. This vulnerability allows an unauthenticated attacker to trick a legitimate user into performing unauthorized actions, potentially exposing customer data or modifying product catalogs and pricing information without proper authorization.
Technical details
The vulnerability is a cross-site request forgery (CSRF) or similar client-side attack in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. It is easily exploitable and requires no authentication, with network-level access via HTTP sufficient for attack delivery. However, successful exploitation requires user interaction—a victim must click a malicious link or visit an attacker-controlled page. While the flaw resides in Guided Search / Experience Manager, scope change indicates attacks can significantly impact downstream systems. Successful exploitation results in unauthorized read access to critical data and limited write access (insert/update/delete) to certain data. Patches are available from Oracle.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed