Sceawere

Vulnerability Detail

CVE-2026-70954UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Commerce Platform DAF Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Commerce Platform
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-18T21:17:53.720Z",
  "pubdate": "2026-08-18T21:17:53.720Z",
  "executiveSummary": "A critical remotely exploitable vulnerability exists within the Oracle Commerce Platform product of Oracle Commerce, specifically residing in the Dynamo Application Framework component. This flaw presents a severe risk to organizational infrastructure by allowing unauthenticated malicious actors to achieve full system compromise through standard network protocols without requiring user interaction or prior credentials.\nThe vulnerability is characterized by a maximum severity CVSS 3.1 Base Score of 9.8, indicating catastrophic impacts across all core information security pillars: confidentiality, integrity, and availability. Successful exploitation grants an attacker complete administrative control, resulting in the total takeover of the affected Oracle Commerce Platform instance.\nGiven the absence of required authentication and the network-accessible vector via HTTP, the attack surface is expansive. Threat actors can execute arbitrary payloads remotely to manipulate underlying system architecture, exfiltrate sensitive data, corrupt database states, or disrupt service operations entirely. Organizations running the impacted software face immediate operational and reputational threats until appropriate remediation measures are deployed.",
  "technicalDetails": "The vulnerability manifests within the Dynamo Application Framework component of the Oracle Commerce Platform product. It affects the supported version 11.4.0. The root cause lies in inadequate input validation or improper handling of incoming HTTP requests processed by the framework, enabling remote code execution or unauthorized access to administrative functions.\nExploitation of this vulnerability requires network access via the HTTP protocol. Because the attack vector is network-based (AV:N) and the attack complexity is low (AC:L), an adversary can transmit maliciously crafted HTTP requests directly to the target application endpoint without needing valid user credentials (PR:N) or any form of user interaction (UI:N).\nThe attack flow proceeds as follows: First, the unauthenticated attacker identifies an exposed Oracle Commerce Platform instance running version 11.4.0. Second, the attacker crafts a specialized HTTP payload designed to exploit the parsing or execution logic within the Dynamo Application Framework. Third, the HTTP request is transmitted across the network to the vulnerable server. Fourth, the Dynamo Application Framework processes the malicious payload insecurely, leading to memory corruption, insecure deserialization, or arbitrary command execution depending on the specific flaw mechanism. Finally, the successful execution of the payload grants the attacker unauthorized control over the application runtime.\nThe post-exploitation impact is absolute. With complete takeover capabilities, the malicious actor achieves high-level privileges within the context of the application process. This allows the attacker to read, modify, or delete sensitive data affecting confidentiality and integrity, as well as terminate services or exhaust resources impacting availability."
}
CVE-2026-70954: Oracle Commerce Platform DAF Vulnerability (CRITICAL Severity, CVSS: 9.8) - Sceawere