Executive brief
Oracle Commerce Guided Search and Experience Manager are components used to power product search and customer experience features in e-commerce platforms. A vulnerability in the Endeca Application Controller allows a low-privileged user with local access to the underlying infrastructure to fully compromise the application, potentially gaining complete control over search functionality and customer data.
Technical details
The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search and Experience Manager version 11.4.0. It is classified as a privilege escalation flaw requiring local access to the infrastructure and low-level privileges to exploit; exploitation is difficult (AC:H). An attacker with local logon credentials and low privileges can achieve complete system compromise, including confidentiality, integrity, and availability impacts, resulting in full takeover of the affected service. A patch or update addressing this issue should be obtained from Oracle's security advisory publication.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-09-15: disclosed: Vulnerability published by Oracle