Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Commerce Platform version 11.4.0 contains a Cross‑Site Request Forgery flaw in the Dynamo Application Framework. The flaw allows a low‑privileged attacker who can reach the web interface over HTTP to send forged requests that an unrelated user is compelled to perform. Successfully exploiting the flaw can give the attacker read access to sensitive data with a high confidentiality impact and the ability to modify or delete some data, resulting in integrity loss. The weakness is a classic CSRF issue (CWE‑352).

Affected Systems

Vulnerable systems are Oracle Commerce Platform 11.4.0 deployed by Oracle Corporation. The advisory notes that the flaw may also affect other products within the Oracle ecosystem through scope changes, but the primary impact is on this version.

Risk and Exploitability

The CVSS base score of 7.6 classifies this as high severity. The EPSS score of less than 1% indicates a low probability of exploitation, but the vulnerability is not in CISA’s KEV catalog. Attackers would need network access to the HTTP interface, low privilege, and an unsuspecting user to trigger the forged request, typically through social engineering or phishing. Without a patch, exposed systems that allow HTTP traffic can be compromised, posing significant confidentiality risks and some integrity breach. The scope change suggests that attackers might also affect other Oracle products if the same framework component is reused.

Generated by OpenCVE AI on August 4, 2026 at 01:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Commerce Platform patch released in July 2026 CPU to version 11.4.0 or later
  • Limit HTTP exposure of the Commerce Platform to trusted networks or employ network segmentation to reduce attack surface
  • Enforce multi‑factor authentication and strict role‑based access controls to mitigate the risk of unauthorized data modification

Generated by OpenCVE AI on August 4, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Data Access and Modification in Oracle Commerce Platform

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Data Access and Modification in Oracle Commerce Platform

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Platform Improper Authorization Vulnerability Allowing Unauthorized Access via HTTP
Weaknesses CWE-200
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Platform Improper Authorization Vulnerability Allowing Unauthorized Access via HTTP
Weaknesses CWE-200
CWE-285
CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:49:28.330Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61132

cve-icon Vulnrichment

Updated: 2026-07-23T18:49:23.412Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:44.500

Modified: 2026-07-27T13:41:41.547

Link: CVE-2026-61132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)