Junglewise Threat Intelligence

CVE-2026-71032: Oracle Commerce Guided Search data access vulnerability

CVE-2026-71032 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search is an e-commerce product used to power product search and recommendation features in online storefronts. An unauthenticated attacker can exploit a vulnerability in the underlying Endeca Application Controller to read sensitive customer or product data, and to modify or delete data—compromising data integrity and potentially affecting customer trust and operational continuity.

Technical details

The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is an easily exploitable, unauthenticated network-accessible vulnerability (CWE class likely involving improper access control or injection) that requires no user interaction. An attacker with network access via HTTP can execute unauthorized read, insert, update, and delete operations against some of the application's accessible data. The scope is marked as changed, indicating potential impact beyond the directly affected product. No patch or fix availability information is currently confirmed in the advisory.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats