Executive brief
Oracle Commerce Guided Search is a search and navigation component used in e-commerce storefronts to help customers find products. An unauthenticated network attacker can exploit a flaw in the Endeca Application Controller to read, modify, or delete product data and other information accessible through the search system, potentially exposing customer or business-critical data and disrupting storefront operations.
Technical details
The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. An unauthenticated attacker with network access via HTTP can exploit this flaw without requiring authentication or user interaction (AC:L, PR:N, UI:N). The vulnerability allows unauthorized read access to a subset of accessible data and unauthorized update, insert, or delete access to some accessible data. The impact scope extends beyond the affected product itself (S:C), potentially compromising other related systems or data stores. No information on patch availability was available at the time of advisory publication.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed