Summary
CVE-2026-70998 is a critical, unauthenticated vulnerability in the Endeca Application Controller (EAC) component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. It allows a remote attacker with no credentials to gain unauthorized access to critical data over HTTP, and Oracle rates it 9.3 (Critical) on the CVSS v3.1 scale. It was disclosed as part of Oracle’s August 2026 Critical Security Patch Update.
Technical details
- Root cause: an easily exploitable flaw in the Endeca Application Controller component that fails to properly restrict access to accessible data.
- Trigger conditions: no authentication or user interaction is required; the attacker only needs network access to the exposed HTTP interface.
- Attack vector: network-based exploitation over HTTP (AV:N, AC:L, PR:N, UI:N).
- Impact: successful exploitation can result in unauthorized access to critical data, or complete access to all data accessible by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The vulnerability has a "Scope: Changed" rating, meaning impact can extend beyond the vulnerable component itself; confidentiality impact is High and integrity impact is Low, with no availability impact.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 (Endeca Application Controller component)
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: apply the fix provided in Oracle’s August 2026 Critical Security Patch Update for Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0.
- If immediate patching is not possible: restrict network access to the Endeca Application Controller and Oracle Commerce Guided Search / Experience Manager HTTP interfaces to trusted internal networks only, and monitor for anomalous unauthenticated requests to these services until the patch can be applied.

