Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the Oracle Commerce Platform component known as the Dynamo Application Framework. The vulnerability permits an attacker without authentication to send specially crafted HTTP requests that grant access to critical data stored by the platform and also allow the attacker to trigger a hang or crash, causing a full denial of service. The weakness originates from improper access control (CWE-284) and missing authentication (CWE-306), leading to a high confidentiality impact and a complete availability loss, with no impact on integrity. The CVSS v3.1 base score of 9.1 reflects a severe risk for exposed systems.

Affected Systems

The affected product is the Oracle Commerce Platform version 11.4.0, as produced by Oracle Corporation. No other version or product is listed as impacted in the available data.

Risk and Exploitability

The exploit is considered easily achievable, requiring only network access over HTTP and no prior authentication. The EPSS score of less than 1% indicates the probability of real-world exploitation is low. The CVSS score of 9.1 places the issue in the critical severity range. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploitation campaigns have been reported. Nonetheless, the high impact combined with the simple attack surface warrants immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Commerce Platform 11.4.0 patch released by Oracle to fix the vulnerability.
  • Restrict inbound HTTP traffic to the Commerce Platform to only trusted networks or IP ranges to limit exposure.
  • Configure application or web-server level monitoring to detect unusual hang or crash events and alert administrators promptly.

Generated by OpenCVE AI on August 4, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access and Denial of Service in Oracle Commerce Platform 11.4.0

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access and Denial of Service in Oracle Commerce Platform 11.4.0

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and DoS in Oracle Commerce Platform 11.4.0

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and DoS in Oracle Commerce Platform 11.4.0
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:50:12.677Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61130

cve-icon Vulnrichment

Updated: 2026-07-23T18:50:08.907Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function