CVE-2026-83239
nicheDifficult-to-Exploit Local Takeover Flaw in Oracle Commerce Guided Search 11.4.0
CVE-2026-83239 is a difficult-to-exploit local vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting supported version 11.4.0. A low-privileged attacker who already has logon access to the server infrastructure where the product executes can trigger the flaw and gain unauthorized access, ultimately resulting in a complete takeover of the affected Oracle Commerce Guided Search / Experience Manager deployment with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N). The vulnerability is rated high severity despite its local vector because successful exploitation compromises the entire product. Organizations running Oracle Commerce with Endeca-based search and experience management on version 11.4.0 are affected. No public proof-of-concept exists, the issue is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83239 to all Oracle Commerce Guided Search / Experience Manager 11.4.0 installations. Because exploitation requires local logon, enforce least-privilege OS account access and tightly control who can authenticate to servers running the Endeca Application Controller. Review local account activity and Endeca service logs on affected hosts for signs of abuse while patching is scheduled.
| Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Endeca Application Controller) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.