Executive brief
Oracle Commerce Guided Search is a product that powers site search and merchandising features in e-commerce platforms. This vulnerability allows attackers with low privileges to manipulate or access sensitive customer data and product information through a cross-site request forgery attack, requiring a customer or administrator to click a malicious link. Successful exploitation could expose confidential business data, customer information, or allow unauthorized changes to product catalogs and pricing.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability is easily exploitable via HTTP and requires low privilege access plus user interaction (a person other than the attacker must be tricked into performing an action). The attack vector is network-based, and successful exploitation allows unauthorized read access to critical data and unauthorized write/delete access to some data accessible by the compromised user. The scope changes, meaning the vulnerability can impact additional products beyond the affected component. No patch information is currently available from the provided advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed