Junglewise Threat Intelligence

CVE-2026-71016: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71016 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used to power product discovery and search in e-commerce platforms. This vulnerability allows an unauthenticated attacker to trick a legitimate user into performing unauthorized actions, potentially exposing customer data or modifying product catalogs and pricing information without proper authorization.

Technical details

The vulnerability is a cross-site request forgery (CSRF) or similar client-side attack in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. It is easily exploitable and requires no authentication, with network-level access via HTTP sufficient for attack delivery. However, successful exploitation requires user interaction—a victim must click a malicious link or visit an attacker-controlled page. While the flaw resides in Guided Search / Experience Manager, scope change indicates attacks can significantly impact downstream systems. Successful exploitation results in unauthorized read access to critical data and limited write access (insert/update/delete) to certain data. Patches are available from Oracle.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats