Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Commerce Platform (Dynamo Application Framework) allows an unauthenticated network attacker to exploit the platform over HTTP, leading to a full compromise of the affected system. This vulnerability results in loss of confidentiality, integrity, and availability, enabling complete takeover of the Oracle Commerce Platform.

Affected Systems

The vulnerability affects Oracle Corporation's Oracle Commerce Platform, specifically version 11.4.0.

Risk and Exploitability

The CVSS of 9.8 indicates a critical severity. Although the EPSS score is below 1%, the low probability does not diminish the high potential impact. The flaw is not currently listed in CISA’s KEV catalog. The attack requires only network access to the HTTP interface and no authentication, making the threat surface wide for any publicly exposed instance of the platform.

Generated by OpenCVE AI on August 4, 2026 at 01:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released in Oracle’s update Oracle Commerce Platform 11.4.0
  • Configure network perimeter controls to block external HTTP traffic to the Commerce Platform until the patch is applied
  • Enforce strict access controls and verify that the platform is not publicly exposed; separate internal and external networks to limit attack exposure

Generated by OpenCVE AI on August 4, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Commerce Platform

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title High-Risk Remote Code Execution Vulnerability in Oracle Commerce Platform 11.4.0

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High-Risk Remote Code Execution Vulnerability in Oracle Commerce Platform 11.4.0
Weaknesses CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:51:14.722Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61131

cve-icon Vulnrichment

Updated: 2026-07-23T18:51:08.870Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:44.393

Modified: 2026-07-27T13:44:49.867

Link: CVE-2026-61131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function