Junglewise Threat Intelligence

CVE-2026-71027: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71027 · Severity: high · CVSS 7.6 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager is an e-commerce platform component that delivers product search and browsing experiences. This vulnerability allows a low-privileged attacker to gain unauthorized access to sensitive commerce data and modify records through a web-based attack that requires victim interaction, potentially affecting customer information, product catalogs, and transaction data stored in the system.

Technical details

This is a cross-site request forgery (CSRF) or similar web-based vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. The vulnerability is exploitable via HTTP by a network-adjacent attacker with low privileges, requiring user interaction (UI:R in CVSS vector). The attack has scope change, meaning it can impact other connected Oracle products beyond the directly vulnerable component. Successful exploitation results in high confidentiality impact (unauthorized read access to critical data) and limited integrity impact (unauthorized modification of some data). No patch details are available in the provided advisory text.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats