Description
Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access via HTTP can exploit an access control weakness in Oracle Commerce Service Center to insert, update, or delete data that should be protected, as well as read restricted information. The flaw requires the attacker to engage a user who is not the attacker himself, limiting the ease of immediate compromise but still allowing an intruder to alter the integrity and confidentiality of the data store if they can create or manipulate user sessions. The vulnerability is a classic insufficient authorization error (CWE‑284).

Affected Systems

Oracle Commerce Service Center version 11.4.0, distributed by Oracle Corporation, is the only version verified to be vulnerable. The product is typically accessed via an HTTP endpoint.

Risk and Exploitability

The CVSS score of 6.1 classifies the issue as moderate. An EPSS score of less than 1 % indicates that widespread exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, attackers must succeed in establishing HTTP connectivity to the vulnerable service and then persuade a non‑attacker user to carry out an action that triggers the flaw. Remote network access over the HTTP interface is the primary entry point, but the necessity of human interaction makes immediate exploitation more difficult.

Generated by OpenCVE AI on August 3, 2026 at 00:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a fixed version of Oracle Commerce Service Center.
  • Restrict HTTP traffic to the Commerce Service Center component via firewall rules or access control lists permitting only trusted IP ranges.
  • Enforce strict authentication and session management for all service‑center endpoints to ensure that only authorized users can perform data‑modification operations.

Generated by OpenCVE AI on August 3, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle Commerce Service Center Allows Unauthorized Data Modification

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification Vulnerability in Oracle Commerce Service Center
Weaknesses CWE-285

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification Vulnerability in Oracle Commerce Service Center
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle commerce Service Center
CPEs cpe:2.3:a:oracle:commerce_service_center:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Service Center
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Commerce Service Center
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:20:01.440Z

Reserved: 2026-03-26T19:48:45.681Z

Link: CVE-2026-34316

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:59.828Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:30:16Z

Weaknesses