CRITICAL
9.1 CVE-2026-71015 Published 18 Aug 2026
Oracle Commerce Guided Search Endeca Application Controller Unauthorized Data Access Flaw
Worried this affects one of your servers?
An unauthorized data access vulnerability affects Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Endeca Application Controller component.
The supported affected version is 11.4.0. The vulnerability is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in:
- Unauthorized creation, deletion, or modification access to critical data or all accessible data
- Unauthorized access to critical data or complete access to all accessible data
The CVSS 3.1 base score is 9.1, with high confidentiality and integrity impacts. CVSS vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Reference: CVE-2026-71015 on NVD
← Back to Security News