Summary
CVE-2026-71026 is a critical vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Endeca Application Controller component. It allows an unauthenticated, remote attacker over HTTP to gain unauthorized access to create, delete, or modify critical data, and to read all accessible system data. Oracle rates this as easily exploitable with a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: a flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.
- Trigger conditions: no authentication or user interaction is required; the vulnerability is exploitable purely via network access.
- Attack vector: Network, over the HTTP protocol.
- Impact: unauthorized creation, deletion, or modification of critical data, plus the ability to read all data accessible to the affected component (high confidentiality and integrity impact; no availability impact per the CVSS vector).
Affected software
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0.
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Security Patch Update (CSPU) for Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. Oracle confirms a patch is available for this CVE.
- If a patch cannot be applied immediately: restrict network exposure of the Endeca Application Controller component (e.g., limit access via network segmentation, firewall rules, or VPN) to reduce the attack surface until patching is complete, and monitor for anomalous data creation/modification/deletion activity on the affected system.

