Executive brief
Oracle Commerce Guided Search and Experience Manager are components used to manage product search and personalization in e-commerce environments. A vulnerability in the Endeca Application Controller allows a low-privileged user with local system access to escalate privileges and take full control of the application, potentially compromising product data, pricing, search results, and customer experience across the online store.
Technical details
This is a privilege escalation vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability requires local (adjacent) access and a low-privilege account on the infrastructure hosting the application, but requires no user interaction. Successful exploitation allows an attacker to achieve complete compromise of the affected service with high impact to confidentiality, integrity, and availability. The attack vector is local (AV:L), access control is low (AC:L), and privilege level required is low (PR:L). A patch or mitigation is not yet confirmed to be available.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed