Executive brief
A critical vulnerability has been identified in the Oracle Commerce Platform, a suite used by businesses to manage online retail and customer experiences. An attacker can exploit this flaw over the internet without needing any login credentials or user interaction. If successful, an attacker could take complete control of the platform, potentially leading to the theft of customer data, disruption of online sales, and full system compromise.
Technical details
This vulnerability exists in the ATG Portals component of Oracle Commerce Platform version 11.4.0. It is classified as easily exploitable, requiring no authentication or user interaction (UI:N). An attacker can exploit this flaw remotely over the network via HTTP (AV:N). A successful exploit results in a complete takeover of the Oracle Commerce Platform, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). While the specific CWE is not detailed in the advisory, the CVSS score and 'takeover' description suggest a critical flaw such as remote code execution or a complete authentication bypass.
Affected products
- Oracle Commerce Platform 11.4.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update.
- 2026-07-21: advisory: NVD published the CVE record.