ZeroHour

CVE-2026-83239

niche

Difficult-to-Exploit Local Takeover Flaw in Oracle Commerce Guided Search 11.4.0

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83239 is a difficult-to-exploit local vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting supported version 11.4.0. A low-privileged attacker who already has logon access to the server infrastructure where the product executes can trigger the flaw and gain unauthorized access, ultimately resulting in a complete takeover of the affected Oracle Commerce Guided Search / Experience Manager deployment with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N). The vulnerability is rated high severity despite its local vector because successful exploitation compromises the entire product. Organizations running Oracle Commerce with Endeca-based search and experience management on version 11.4.0 are affected. No public proof-of-concept exists, the issue is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83239 to all Oracle Commerce Guided Search / Experience Manager 11.4.0 installations. Because exploitation requires local logon, enforce least-privilege OS account access and tightly control who can authenticate to servers running the Endeca Application Controller. Review local account activity and Endeca service logs on affected hosts for signs of abuse while patching is scheduled.

Affected
Oracle Commerce Guided Search / Oracle Commerce Experience Manager (Endeca Application Controller)
Estimated exposure
nicheLikely hundreds to low thousands of enterprise deployments worldwide — Oracle Commerce/Endeca is an on-premises enterprise e-commerce platform licensed to a limited base of large organizations, and this flaw further requires local logon access, so only a small fraction of internet-facing commerce systems are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.