CRITICAL 9.1 CVE-2026-71014 Published 18 Aug 2026

Oracle Commerce Guided Search Endeca Application Controller Data Access Flaw

Worried this affects one of your servers?

A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Endeca Application Controller). The issue is an unauthorized data access and modification vulnerability affecting version 11.4.0.

The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion or modification of critical data, as well as unauthorized access to critical data or complete access to all accessible data.

  • Affected version: 11.4.0
  • Attack vector: network via HTTP
  • Authentication: none required
  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)

Reference: CVE-2026-71014 on NVD

← Back to Security News