CRITICAL 9.1 CVE-2026-70994 Published 18 Aug 2026

Oracle Commerce Guided Search Endeca Application Controller Data Access and DoS Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Endeca Application Controller). The supported version affected is 11.4.0.

The flaw is an easily exploitable data access and denial-of-service vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the product.

Successful attacks can result in unauthorized access to critical data or complete access to all accessible data, and can cause a hang or frequently repeatable crash (complete DoS).

  • Affected version: 11.4.0
  • Attack vector: network via HTTP, no authentication required
  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Availability impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)

Reference: CVE-2026-70994 on NVD

← Back to Security News