CRITICAL 9.1 CVE-2026-71026 Published 18 Aug 2026

Oracle Commerce Endeca Application Controller Unauthenticated Data Access Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically in the Endeca Application Controller component. The supported affected version is 11.4.0.

This unauthenticated data access and integrity vulnerability is easily exploitable by an attacker with network access via HTTP. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data, as well as unauthorized access to critical data or complete access to all accessible data.

  • Affected version: 11.4.0
  • Attack vector: network access via HTTP, no authentication required
  • Impact: unauthorized modification and access to critical or all accessible data
  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts); CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Reference: CVE-2026-71026 on NVD

← Back to Security News