Junglewise Threat Intelligence

CVE-2026-34316: Oracle Commerce Service Center unauthorized data access via HTTP

CVE-2026-34316 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Commerce Service Center, a platform used by customer service teams to manage commerce operations, contains a vulnerability that could allow an unauthorized person to view or modify business data. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. If successful, this could lead to unauthorized changes to customer or order information and potentially impact other connected systems.

Technical details

A vulnerability in the Commerce Service Center component of Oracle Commerce (version 11.4.0) allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability is characterized by a 'scope change' (CVSS S:C), suggesting that an exploit could impact components beyond the immediate security scope of the Service Center. Exploitation requires human interaction from a legitimate user (UI:R), which is consistent with Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) patterns. Attackers can achieve unauthorized read, update, insert, or delete access to a subset of the application's data. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Commerce Service Center 11.4.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References