Summary
CVE-2026-71014 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. It allows an unauthenticated, network-based attacker communicating over HTTP to compromise the system, potentially resulting in unauthorized creation, deletion, and modification of data as well as complete access to all accessible data. Oracle rates this issue CRITICAL with a CVSS v3.1 base score of 9.1.
Technical details
- Root cause: A flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Experience Manager.
- Trigger conditions: No authentication or user interaction is required; the vulnerability is remotely exploitable over HTTP.
- Attack vector: Network (AV:N), with low attack complexity (AC:L) and no privileges required (PR:N).
- Impact: High confidentiality and integrity impact — unauthorized data creation, deletion, modification, and complete access to all accessible data. No availability impact is reported.
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 (Endeca Application Controller component).
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update for August 2026, which addresses CVE-2026-71014, to all affected Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 deployments.
- If patching cannot be applied immediately: Restrict network access to the Endeca Application Controller / Oracle Commerce Guided Search and Experience Manager endpoints to trusted internal networks only, and monitor exposed HTTP interfaces for anomalous requests until the patch can be deployed.

