Executive brief
Oracle Commerce Guided Search and Experience Manager are commerce platform components that manage product search and customer experience. A network-accessible vulnerability allows unauthenticated attackers to bypass authentication controls, exposing sensitive customer and product data and potentially disrupting service availability. This could lead to unauthorized access to critical business information or temporary service outages.
Technical details
An authentication bypass vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability is difficult to exploit but requires no authentication and is accessible remotely via HTTP to an unauthenticated attacker. Successful exploitation allows unauthorized access to critical data stored in the system and partial denial of service of the affected component. No information about patch availability is publicly available at this time.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed