CRITICAL 9.1 CVE-2026-71015 Published 18 Aug 2026

Oracle Commerce Guided Search Endeca Application Controller Unauthorized Data Access Flaw

Worried this affects one of your servers?

An unauthorized data access vulnerability affects Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Endeca Application Controller component.

The supported affected version is 11.4.0. The vulnerability is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in:

  • Unauthorized creation, deletion, or modification access to critical data or all accessible data
  • Unauthorized access to critical data or complete access to all accessible data

The CVSS 3.1 base score is 9.1, with high confidentiality and integrity impacts. CVSS vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Reference: CVE-2026-71015 on NVD

← Back to Security News