Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows attackers without authentication to send HTTP requests to the Oracle Commerce Platform 11.4.0, specifically the Dynamo Application Framework component, and to perform unauthorized update, insert or delete operations on data, read restricted data, or deliver a partial denial of service. The weakness is a flaw in the platform’s access control, classified as CWE‑284. Successful exploitation results in moderate confidentiality, integrity and availability impacts, as reflected by the CVSS 3.1 Base Score of 7.3.

Affected Systems

Affected is Oracle Corporation’s Oracle Commerce Platform, version 11.4.0. The issue resides in the Dynamo Application Framework component. No other versions or products are listed as impacted.

Risk and Exploitability

The EPSS score is indicated as < 1 %, meaning exploitation is considered unlikely but not impossible. The CVSS score of 7.3 signals moderate severity, and the vulnerability is not listed in CISA KEV, so there are no known active exploits. Attackers can trigger the vulnerability over an unauthenticated HTTP connection, eliminating the need for user credentials. Deploying the official patch or restricting HTTP traffic to trusted sources mitigates the risk.

Generated by OpenCVE AI on August 4, 2026 at 01:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle July 2026 patch that addresses the unauthenticated HTTP vulnerability in Commerce Platform 11.4.0, as referenced in Oracle’s CPU alert.
  • Restrict inbound HTTP traffic to the Commerce Platform using firewall rules or network segmentation so that only trusted IP ranges can reach the vulnerable endpoints.
  • Enforce role‑based authentication and access control on the Dynamo Application Framework, ensuring that data‑modification and read operations require proper user privileges before execution.

Generated by OpenCVE AI on August 4, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enabling Unauthorized Data Modification and Partial Denial of Service in Oracle Commerce Platform

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enabling Unauthorized Data Modification and Partial Denial of Service in Oracle Commerce Platform

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification and Partial DoS in Oracle Commerce Platform

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification and Partial DoS in Oracle Commerce Platform
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:42:25.977Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61136

cve-icon Vulnrichment

Updated: 2026-07-23T18:42:22.309Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses