CVE-2026-70995: Critical severity Oracle Oracle Commerce Guided Search / Oracle Commerce Experience Manager vulnerability
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Oracle Commerce Guided Search / Oracle Commerce Experience Manager deployments using the Endeca Application Controller in supported version 11.4.0 are affected. Exposure requires network access to the vulnerable component over HTTP.
Does exploitation require credentials or user interaction?
No. An unauthenticated attacker can exploit the issue remotely over the network, and no user interaction is required.
What is the potential impact of a successful exploit?
A successful attack can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, with high impact to confidentiality, integrity, and availability.