Sceawere

Vulnerability Detail

CVE-2026-61130Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Platform Unauthorized Access

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Platform
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:44.280Z",
  "pubdate": "2026-07-21T22:18:44.280Z",
  "executiveSummary": "The Oracle Commerce Platform, specifically the Dynamo Application Framework component, contains a critical security vulnerability affecting version 11.4.0. This flaw permits an unauthenticated attacker with network access via HTTP to compromise the system, leading to severe confidentiality and availability impacts.\nThe vulnerability allows unauthorized access to critical or sensitive data stored within the Oracle Commerce Platform. Furthermore, the attacker possesses the capability to induce a complete denial-of-service (DoS) condition, resulting in a hang or frequently repeatable system crash.\nGiven the CVSS 3.1 Base Score of 9.1, the risk is classified as critical. The attack complexity is low, and the exploit does not require user interaction or prior authentication. Successful exploitation allows an attacker to bypass standard security controls to exfiltrate data or disrupt business-critical operations. Organizations utilizing the affected version of the Dynamo Application Framework should prioritize defensive measures to mitigate unauthorized access and service interruption.",
  "technicalDetails": "The vulnerability resides within the Dynamo Application Framework of the Oracle Commerce Platform, version 11.4.0. The security flaw originates from inadequate authentication and authorization mechanisms that fail to properly validate requests targeting the framework's internal endpoints.\nExploitation is conducted via the HTTP protocol over a network interface. As the vulnerability requires no authentication and no specific user interaction, it represents a high-exposure entry point for remote attackers. The attack flow initiates with the attacker crafting specialized HTTP requests directed at exposed components within the Dynamo Application Framework. Because the framework lacks sufficient access control enforcement, the system interprets these requests as legitimate, granting the attacker unauthorized interaction with the underlying application data structures.\nIn the context of confidentiality, the exploitation allows the attacker to query or retrieve sensitive information that should be restricted to authenticated administrative users. By manipulating inputs, an attacker can bypass traditional session-based security, gaining visibility into internal data sets managed by the Oracle Commerce Platform.\nIn the context of availability, the vulnerability facilitates a DoS vector. By submitting specifically formatted payloads or triggering resource-intensive functions within the Dynamo Application Framework that are not correctly rate-limited or bounded, the attacker can cause the application to hang or trigger a complete crash. The repeatability of these crashes indicates that the vulnerability affects core process handling or memory management within the framework's architecture, allowing an attacker to render the platform inaccessible to legitimate users indefinitely.\nThe exploitation process follows a sequential pattern: first, reconnaissance of the target infrastructure to identify the presence of the vulnerable Dynamo Application Framework; second, the injection of malicious HTTP requests that leverage the absence of authentication protocols; and third, the delivery of the payload designed to either extract sensitive data or overwhelm the application process to force a crash. Because the attack vector is network-accessible and requires no privileges, it bypasses standard authorization checks, leaving the platform exposed to any threat actor capable of reaching the HTTP service."
}
CVE-2026-61130: Oracle Commerce Platform Unauthorized Access (CRITICAL Severity, CVSS: 9.1) - Sceawere