SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61161 2026-07-21

Oracle Commerce Guided Search Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-61161)

"A critical, easily exploitable vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager lets an unauthenticated attacker take over the product over the network with no user interaction."

A critical, easily exploitable vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager lets an unauthenticated attacker take over the product over the network with no user interaction.

What Is It

CVE-2026-61161 is a critical vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce, specifically in the Endeca Application Controller component. According to Oracle's advisory (via NVD), the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in full takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, high confidentiality, integrity, and availability impact.

Why It Matters

The combination of network attack vector, low attack complexity, no required privileges, and no user interaction means an attacker needs only HTTP reachability to the affected service. Because a successful attack results in complete takeover, the confidentiality, integrity, and availability impacts are all rated high. There is no CISA KEV entry in the supplied source material, so active exploitation is not confirmed here; however, the 9.8 score and "easily exploitable" characterization make this a high-priority patching target.

What's Vulnerable

The supplied NVD record lists the affected product as Oracle Commerce Guided Search / Oracle Commerce Experience Manager (vendor: Oracle Corporation), affected version 11.4.0. The vulnerable component is the Endeca Application Controller. No specific affected CPE entries were provided in the source data.

Patch Status

Oracle addresses this issue in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the associated fixes to affected 11.4.0 deployments. No CISA-mandated required action was included in the supplied source material.

Sources