CRITICAL
9.8 CVE-2026-70995 Published 18 Aug 2026
Oracle Commerce Guided Search Endeca Application Controller Takeover Vulnerability
Worried this affects one of your servers?
A remote takeover vulnerability has been disclosed in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Endeca Application Controller component. The supported affected version is 11.4.0.
The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, allowing them to compromise the product. Successful attacks can result in full takeover of the affected Oracle Commerce installation.
- Affected version: 11.4.0
- Attack vector: unauthenticated network access via HTTP
- Impact: full takeover; CVSS 3.1 base score 9.8 (high confidentiality, integrity, and availability impacts)
Reference: CVE-2026-70995 on NVD
← Back to Security News