Junglewise Threat Intelligence

CVE-2026-71018: Oracle Commerce Guided Search XSS or injection in Endeca Application Controller

CVE-2026-71018 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are used to power product search and discovery interfaces in e-commerce platforms. This vulnerability allows an unauthenticated attacker to access sensitive customer data and modify commerce data through HTTP requests with minimal user interaction, potentially impacting customer privacy and transaction integrity across connected systems.

Technical details

This is an easily exploitable vulnerability in the Endeca Application Controller component affecting Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability requires network-accessible HTTP connectivity and can be exploited by an unauthenticated attacker with user interaction (clicking a malicious link). The attack has scope change implications, meaning compromise of the affected component can impact other connected Oracle Commerce products. Successful exploitation results in high confidentiality impact (unauthorized read access to critical data) and limited integrity impact (unauthorized insert/update/delete of some data), but no availability impact. Patches or mitigations are not confirmed in the available advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats