Executive brief
Oracle Commerce Guided Search and Experience Manager are used to power product search and discovery interfaces in e-commerce platforms. This vulnerability allows an unauthenticated attacker to access sensitive customer data and modify commerce data through HTTP requests with minimal user interaction, potentially impacting customer privacy and transaction integrity across connected systems.
Technical details
This is an easily exploitable vulnerability in the Endeca Application Controller component affecting Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability requires network-accessible HTTP connectivity and can be exploited by an unauthenticated attacker with user interaction (clicking a malicious link). The attack has scope change implications, meaning compromise of the affected component can impact other connected Oracle Commerce products. Successful exploitation results in high confidentiality impact (unauthorized read access to critical data) and limited integrity impact (unauthorized insert/update/delete of some data), but no availability impact. Patches or mitigations are not confirmed in the available advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed