Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Commerce Platform version 11.4.0 contains a flaw in the Dynamo Application Framework that permits an unauthenticated attacker to exploit the LDAP interface over the network and bypass authentication. By sending a crafted LDAP request, the attacker can read critical data stored in the platform without any credentials. This vulnerability does not affect integrity or availability, but it results in a substantial confidentiality breach.

Affected Systems

Oracle Corporation’s Oracle Commerce Platform 11.4.0 is the only affected product. The description states that the flaw resides in the commerce framework component and requires network access to the exposed LDAP service. The input does not specify whether other Oracle products are impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low to moderate likelihood of exploitation at present. The vulnerability is not currently listed in CISA’s KEV catalog, but it enables unauthenticated data exposure and therefore poses a serious threat to confidentiality. Based on the description, the likely attack vector is an external host reaching the LDAP service over the network.

Generated by OpenCVE AI on August 5, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle CPU release‑Jul2026 patch for Oracle Commerce Platform 11.4.0 that fixes the Dynamo Application Framework flaw.
  • Restrict external network access to the LDAP service by configuring firewall rules or network segmentation so that only trusted hosts can reach the LDAP port.
  • Enable application‑level logging and monitor for anomalous LDAP activity or privilege escalation attempts.

Generated by OpenCVE AI on August 5, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Data Exposure in Oracle Commerce Platform 11.4.0

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Data Exposure in Oracle Commerce Platform 11.4.0

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Enables Unauthorized Data Exposure in Oracle Commerce Platform
Weaknesses CWE-285
CWE-288

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Enables Unauthorized Data Exposure in Oracle Commerce Platform
Weaknesses CWE-200
CWE-285
CWE-288
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:48:44.685Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61133

cve-icon Vulnrichment

Updated: 2026-07-23T18:48:40.516Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:44.617

Modified: 2026-07-27T13:41:09.277

Link: CVE-2026-61133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor