Junglewise Threat Intelligence

CVE-2026-71021: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71021 · Severity: high · CVSS 7.6 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are e-commerce platforms used to deliver search and product browsing experiences to customers. A cross-site request forgery (CSRF) vulnerability in the Endeca Application Controller allows an attacker to trick authenticated users into performing unauthorized actions—such as modifying or deleting product data—by visiting a malicious website. This could lead to data corruption, unauthorized access to customer information, or disruption of the online storefront.

Technical details

The vulnerability is a cross-site request forgery (CSRF) affecting the Endeca Application Controller component in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw requires low privileges and network access via HTTP, with successful exploitation requiring user interaction (the user must visit a malicious site while authenticated). An attacker can leverage this to perform unauthorized data modifications, insertions, or deletions, and potentially access sensitive commerce data. The scope is marked as changed, indicating that exploitation may impact additional products beyond the direct target. Oracle has published a security advisory addressing this issue.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: other: CVE-2026-71021 assigned

References

Related threats