Executive brief
Oracle Commerce Guided Search and Commerce Experience Manager are used in e-commerce platforms to deliver search and merchandising capabilities. An unauthenticated attacker on the network can exploit this vulnerability to view, create, delete, or modify customer data and product information without authorization, potentially compromising sensitive business and customer information.
Technical details
This vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is an easily exploitable flaw that allows unauthenticated remote attackers with network access to send specially crafted HTTP requests. The vulnerability permits unauthorized read and write access to critical data within the application. No user interaction or authentication is required to exploit this issue, making it a high-impact network-level threat. Patch availability has not been confirmed in the advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed