Junglewise Threat Intelligence

CVE-2026-71030: Oracle Commerce Guided Search unauthorized data access in Endeca Application Controller

CVE-2026-71030 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search is a search and navigation component used in e-commerce storefronts to help customers find products. An unauthenticated network attacker can exploit a flaw in the Endeca Application Controller to read, modify, or delete product data and other information accessible through the search system, potentially exposing customer or business-critical data and disrupting storefront operations.

Technical details

The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. An unauthenticated attacker with network access via HTTP can exploit this flaw without requiring authentication or user interaction (AC:L, PR:N, UI:N). The vulnerability allows unauthorized read access to a subset of accessible data and unauthorized update, insert, or delete access to some accessible data. The impact scope extends beyond the affected product itself (S:C), potentially compromising other related systems or data stores. No information on patch availability was available at the time of advisory publication.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats