Sceawere
Vulnerability Detail
CVE-2026-61130Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Commerce Platform Unauthorized Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Commerce Platform
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-07-21T22:18:44.280Z",
"pubdate": "2026-07-21T22:18:44.280Z",
"executiveSummary": "The Oracle Commerce Platform, specifically the Dynamo Application Framework component, contains a critical security vulnerability affecting version 11.4.0. This flaw permits an unauthenticated attacker with network access via HTTP to compromise the system, leading to severe confidentiality and availability impacts.\nThe vulnerability allows unauthorized access to critical or sensitive data stored within the Oracle Commerce Platform. Furthermore, the attacker possesses the capability to induce a complete denial-of-service (DoS) condition, resulting in a hang or frequently repeatable system crash.\nGiven the CVSS 3.1 Base Score of 9.1, the risk is classified as critical. The attack complexity is low, and the exploit does not require user interaction or prior authentication. Successful exploitation allows an attacker to bypass standard security controls to exfiltrate data or disrupt business-critical operations. Organizations utilizing the affected version of the Dynamo Application Framework should prioritize defensive measures to mitigate unauthorized access and service interruption.",
"technicalDetails": "The vulnerability resides within the Dynamo Application Framework of the Oracle Commerce Platform, version 11.4.0. The security flaw originates from inadequate authentication and authorization mechanisms that fail to properly validate requests targeting the framework's internal endpoints.\nExploitation is conducted via the HTTP protocol over a network interface. As the vulnerability requires no authentication and no specific user interaction, it represents a high-exposure entry point for remote attackers. The attack flow initiates with the attacker crafting specialized HTTP requests directed at exposed components within the Dynamo Application Framework. Because the framework lacks sufficient access control enforcement, the system interprets these requests as legitimate, granting the attacker unauthorized interaction with the underlying application data structures.\nIn the context of confidentiality, the exploitation allows the attacker to query or retrieve sensitive information that should be restricted to authenticated administrative users. By manipulating inputs, an attacker can bypass traditional session-based security, gaining visibility into internal data sets managed by the Oracle Commerce Platform.\nIn the context of availability, the vulnerability facilitates a DoS vector. By submitting specifically formatted payloads or triggering resource-intensive functions within the Dynamo Application Framework that are not correctly rate-limited or bounded, the attacker can cause the application to hang or trigger a complete crash. The repeatability of these crashes indicates that the vulnerability affects core process handling or memory management within the framework's architecture, allowing an attacker to render the platform inaccessible to legitimate users indefinitely.\nThe exploitation process follows a sequential pattern: first, reconnaissance of the target infrastructure to identify the presence of the vulnerable Dynamo Application Framework; second, the injection of malicious HTTP requests that leverage the absence of authentication protocols; and third, the delivery of the payload designed to either extract sensitive data or overwhelm the application process to force a crash. Because the attack vector is network-accessible and requires no privileges, it bypasses standard authorization checks, leaving the platform exposed to any threat actor capable of reaching the HTTP service."
}