Junglewise Threat Intelligence

CVE-2026-71033: Oracle Commerce Guided Search authentication bypass in Endeca Application Controller

CVE-2026-71033 · Severity: medium · CVSS 5.5 · Published 2026-08-18

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are search and product discovery tools used in e-commerce platforms. A vulnerability in the Endeca Application Controller component allows a low-privileged user with local access to the infrastructure to bypass authentication controls and access all searchable product and customer data without authorization. This could expose sensitive business data and customer information to unauthorized parties.

Technical details

The vulnerability is an authentication bypass or privilege escalation issue in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. It requires local infrastructure access and low-level privileges on the system where the component runs. An authenticated attacker can exploit this to gain unauthorized access to critical data and bypass intended access controls. The vulnerability impacts data confidentiality but not integrity or availability. Oracle has published this issue and patches may be available through the vendor's critical patch updates.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-08-18: disclosed

References

Related threats