Executive brief
Oracle Commerce Service Center, a platform used by customer service teams to manage commerce operations, contains a vulnerability that could allow an unauthorized person to view or modify business data. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. If successful, this could lead to unauthorized changes to customer or order information and potentially impact other connected systems.
Technical details
A vulnerability in the Commerce Service Center component of Oracle Commerce (version 11.4.0) allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability is characterized by a 'scope change' (CVSS S:C), suggesting that an exploit could impact components beyond the immediate security scope of the Service Center. Exploitation requires human interaction from a legitimate user (UI:R), which is consistent with Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) patterns. Attackers can achieve unauthorized read, update, insert, or delete access to a subset of the application's data. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Commerce Service Center 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published