Junglewise Threat Intelligence

CVE-2026-71031: Oracle Commerce Guided Search cross-site request forgery

CVE-2026-71031 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are tools used by e-commerce businesses to manage product search and user experience on online storefronts. A vulnerability in the Endeca Application Controller component allows attackers to trick users into making unauthorized changes to product data or accessing sensitive information without authentication. Successful exploitation could result in product catalog corruption, data theft, or unauthorized modifications to e-commerce operations.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. The vulnerability is easily exploitable and requires no authentication, but does require user interaction (social engineering or session hijacking) to trigger. Attackers with network access via HTTP can exploit this to perform unauthorized data modification (insert, update, delete) and read access to sensitive e-commerce data. The scope change indicates that successful exploitation may impact other integrated Oracle Commerce systems beyond the directly vulnerable component. No information on patch availability was available in the advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats