Junglewise Threat Intelligence

CVE-2026-83239: Oracle Commerce Guided Search privilege escalation in Endeca Application Controller

CVE-2026-83239 · Severity: high · CVSS 7 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used to power product search and customer experience features in e-commerce platforms. A vulnerability in the Endeca Application Controller allows a low-privileged user with local access to the underlying infrastructure to fully compromise the application, potentially gaining complete control over search functionality and customer data.

Technical details

The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search and Experience Manager version 11.4.0. It is classified as a privilege escalation flaw requiring local access to the infrastructure and low-level privileges to exploit; exploitation is difficult (AC:H). An attacker with local logon credentials and low privileges can achieve complete system compromise, including confidentiality, integrity, and availability impacts, resulting in full takeover of the affected service. A patch or update addressing this issue should be obtained from Oracle's security advisory publication.

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed: Vulnerability published by Oracle

References

Related threats