Junglewise Threat Intelligence

CVE-2026-71025: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71025 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are tools used to manage product search and shopping experiences in e-commerce platforms. An unauthenticated attacker can exploit a cross-site request forgery vulnerability via a malicious web link to modify or delete product data and read sensitive information, but only if a logged-in administrator clicks the link. Successful exploitation could compromise product catalogs, customer data visibility, and platform integrity.

Technical details

The vulnerability is a cross-site request forgery (CSRF) flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is easily exploitable over the network via HTTP without authentication, but requires user interaction (UI:R) from an administrator or authorized user. The scope is changed, indicating the vulnerability can impact additional products beyond the directly affected component. A successful attack grants an unauthenticated attacker unauthorized read access to subset of accessible data and update/insert/delete access to some accessible data. Patches or workarounds have not been publicly confirmed at this time.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats