Summary
CVE-2026-70994 is a critical, unauthenticated vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, residing in the Endeca Application Controller component. An attacker with only network access via HTTP can exploit the flaw without credentials to gain unauthorized access to data and to cause a denial-of-service condition. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: A flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Trigger conditions: No authentication or user interaction is required; the flaw is described by Oracle as "easily exploitable."
- Attack vector: Network access via HTTP.
- Impact: Unauthorized access to critical data, up to complete access to all data accessible to the application, and the ability to cause a hang or frequently repeatable crash (complete denial of service).
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0.
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update (CSPU) for August 2026, which addresses this vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. Oracle strongly recommends applying the security patches as soon as possible.
- If patching cannot occur immediately: Restrict network access to the Endeca Application Controller / Oracle Commerce Guided Search components to trusted internal networks only, and monitor exposed instances for anomalous HTTP requests until the patch is applied.

