Summary
CVE-2026-70996 is a high-severity vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. It allows an unauthenticated, network-based attacker to gain unauthorized access to critical data over HTTP without any user interaction. Oracle rates it 8.6 (High) and disclosed it in the August 2026 Critical Security Patch Update.
Technical details
- Root cause: A flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Trigger conditions: Exploitation requires no authentication and no user interaction; Oracle describes the flaw as "easily exploitable."
- Attack vector: Network, via HTTP — accessible to any attacker with network access to the affected component.
- Impact: Unauthorized access to critical data (confidentiality impact: High). The CVSS vector reflects a scope change (S:C), meaning impact can extend beyond the vulnerable component itself. No integrity or availability impact is recorded.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Security Patch Update (CSPU) for Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0.
- If patching cannot be performed immediately: Restrict network access to the Endeca Application Controller / Oracle Commerce environment to trusted networks only, and monitor for anomalous unauthenticated HTTP requests to the affected component until the patch can be applied.

