Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Commerce Platform contains a flaw in the Dynamo Application Framework component that permits an unauthenticated attacker who can reach the platform over HTTP to create, delete, or modify critical data. This unauthorized manipulation of data results in both confidentiality and integrity compromise of all Oracle Commerce Platform accessible data, as the attacker can effectively alter or erase legitimate information without authentication. Based on the description, it is inferred that the vulnerability does not provide code execution but offers full control over business data within the platform.

Affected Systems

Affected systems are Oracle Corporation’s Oracle Commerce Platform, specifically version 11.4.0. The flaw affects the Dynamo Application Framework subsystem of the platform. No other versions are listed as vulnerable in the current CNA data, so organizations running 11.4.0 should verify whether any security releases that address this issue have been applied.

Risk and Exploitability

The CVSS 3.1 base score of 7.4 denotes high severity with high impact on confidentiality and integrity, but the EPSS score is below 1 % and the vulnerability is not listed in CISA's KEV catalog, indicating limited public exploitation data. The attack vector is network‑based over HTTP, requiring no authentication. An attacker who succeeds can fully ingest, modify, or delete critical data within the platform, effectively disrupting business operations. While exploitation is described as difficult, the potential business damage warrants prompt attention.

Generated by OpenCVE AI on August 4, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle Commerce Platform patch that includes the fix for the Dynamo Application Framework vulnerability.
  • Restrict HTTP access to the Commerce Platform to trusted IP ranges or VPN‑only connections to limit exposure to unauthenticated attackers.
  • Configure application firewall rules to block or heavily throttle operations that alter critical data unless performed by authenticated administrator accounts, and enable logging and alerting for suspicious data modification attempts.

Generated by OpenCVE AI on August 4, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Commerce Platform 11.4.0

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Commerce Platform 11.4.0

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Exploitation in Oracle Commerce Platform via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Exploitation in Oracle Commerce Platform via HTTP
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:47:20.938Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61135

cve-icon Vulnrichment

Updated: 2026-07-23T18:47:07.964Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function