Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability exists in the Oracle Commerce Platform 11.4.0 component Dynamo Application Framework. An attacker with low privileges who can reach the system over HTTP could exploit the flaw to create, delete or modify critical data, affecting confidentiality and integrity of the platform.

Affected Systems

The affected product is Oracle Commerce Platform version 11.4.0. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.8 reflects moderate severity. Exploitation is considered difficult and the EPSS score is below 1%, indicating a low probability of real‑world attacks. The vulnerability is not listed in CISA’s KEV catalog. Attack would likely be performed over a network from a low‑privileged account using HTTP, with no user interaction required.

Generated by OpenCVE AI on August 4, 2026 at 01:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Commerce Platform to a patched release when one becomes available
  • Restrict HTTP access to the Commerce Platform to trusted internal networks only
  • Enforce least privilege for all user accounts, periodically review permissions
  • Configure logging and alerting for anomalous data modification activity

Generated by OpenCVE AI on August 4, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Platform 11.4.0 Data Modification Vulnerability

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Oracle Commerce Platform 11.4.0 Data Modification Vulnerability

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Commerce Platform via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Commerce Platform via HTTP
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:48:06.910Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61134

cve-icon Vulnrichment

Updated: 2026-07-23T18:48:00.750Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:44.737

Modified: 2026-07-27T13:38:34.397

Link: CVE-2026-61134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses