Junglewise Threat Intelligence

CVE-2026-83253: Oracle Commerce Guided Search privilege escalation in Endeca Application Controller

CVE-2026-83253 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Commerce Experience Manager, Oracle Commerce Guided Search. Vendors: Oracle.

Executive brief

Oracle Commerce Guided Search and Experience Manager are components used to power product search and discovery in e-commerce platforms. A vulnerability in the Endeca Application Controller allows an authenticated local attacker to gain complete control of the system, requiring user interaction to exploit. Successful compromise could lead to unauthorized access to customer data, modification of search results or pricing, and service disruption.

Technical details

This is a local privilege escalation vulnerability affecting the Endeca Application Controller component in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The vulnerability requires an unauthenticated attacker with local access to the infrastructure and requires user interaction from another party to successfully exploit. The attack results in complete system compromise (confidentiality, integrity, and availability impacts). The vulnerability has a CVSS 3.1 score of 7.8 with a local attack vector (AV:L), low attack complexity (AC:L), no privilege requirements (PR:N), and requires user interaction (UI:R).

Affected products

  • Oracle Commerce Guided Search 11.4.0
  • Oracle Commerce Experience Manager 11.4.0

Timeline

  • 2026-09-15: disclosed: Vulnerability announced by Oracle

References

Related threats