Junglewise Threat Intelligence

CVE-2026-71023: Oracle Commerce Guided Search data integrity bypass

CVE-2026-71023 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search / Experience Manager is a product that powers search and content management for e-commerce platforms. An unauthenticated attacker can exploit this vulnerability over the network to create, delete, or modify critical business data without authorization, potentially compromising product catalogs, pricing, and customer-facing content.

Technical details

This vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is an easily exploitable flaw that allows unauthenticated attackers with network access via HTTP to modify or delete critical data. The vulnerability requires no user interaction or authentication, and the network vector is the primary attack path. Successful exploitation results in unauthorized modification and deletion of data with high integrity impact.

Affected products

  • Oracle Commerce Guided Search 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats