Executive brief
Oracle Commerce Guided Search and Experience Manager are search and product discovery tools used in e-commerce platforms. A vulnerability in the Endeca Application Controller component allows a low-privileged user with local access to the infrastructure to bypass authentication controls and access all searchable product and customer data without authorization. This could expose sensitive business data and customer information to unauthorized parties.
Technical details
The vulnerability is an authentication bypass or privilege escalation issue in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager version 11.4.0. It requires local infrastructure access and low-level privileges on the system where the component runs. An authenticated attacker can exploit this to gain unauthorized access to critical data and bypass intended access controls. The vulnerability impacts data confidentiality but not integrity or availability. Oracle has published this issue and patches may be available through the vendor's critical patch updates.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed