Summary
CVE-2026-70995 is a critical, unauthenticated remote code execution vulnerability affecting the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Oracle rates it 9.8 (Critical) and describes it as "easily exploitable" by an attacker with only network access via HTTP, requiring no authentication or user interaction, resulting in complete compromise of confidentiality, integrity, and availability.
Technical details
- Root cause: A flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Trigger conditions: Attacker sends requests over HTTP to the exposed Endeca Application Controller; no credentials or prior access needed.
- Attack vector: Network (remote, over HTTP), low attack complexity, no privileges required, no user interaction.
- Impact: Complete system compromise — high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update (CSPU) for Oracle Commerce, which addresses this vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0.
- If immediate patching is not possible: Restrict network access to the Endeca Application Controller and any Oracle Commerce Guided Search/Experience Manager endpoints to trusted internal networks only, and monitor for anomalous HTTP requests to these components until the patch can be applied.

