Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Commerce Platform 11.4.0’s Dynamo Application Framework permits an unauthenticated attacker to compromise the platform over HTTP. The vulnerability is a classic authentication bypass (CWE-287 and CWE-306) that allows an attacker with network reachability to gain full control of the Commerce Platform, exposing all stored data and services. The CVSS 3.1 base score of 8.1 reflects severe confidentiality, integrity, and availability impacts.

Affected Systems

Oracle Corporation’s Oracle Commerce Platform 11.4.0 is affected. This product uses the Dynamo Application Framework for application logic and is deployed to deliver e‑commerce services. No other version or product is listed as impacted.

Risk and Exploitability

While the high CVSS score signals significant potential damage, the EPSS score of less than 1 % indicates that exploitation is currently rare and no public campaigns have been documented. The vulnerability can be triggered over an open network connection to the HTTP interface without any credentials, making it a straightforward remote attack. Since the issue is not listed in CISA’s KEV catalog, there is no confirmed exploitation evidence, yet the possibility of a complete platform takeover warrants prompt action.

Generated by OpenCVE AI on August 4, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch for Oracle Commerce Platform 11.4.0 as announced in Oracle’s advisory.
  • Restrict inbound HTTP access to the platform by configuring firewalls or network ACLs so that only trusted IP addresses can reach the affected services.
  • If a patch is not immediately available, harden the Dynamo Application Framework by disabling exposed endpoints and enforcing stricter authentication checks where possible to reduce the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass Allowing Full Oracle Commerce Platform Takeover

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attack Enables Platform Takeover via HTTP

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attack Enables Platform Takeover via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle commerce Platform
CPEs cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle commerce Platform
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Commerce Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:46:27.007Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61137

cve-icon Vulnrichment

Updated: 2026-07-23T18:46:23.256Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function