Junglewise Threat Intelligence

CVE-2026-61130: Oracle Commerce Platform data breach and DoS in Dynamo Application Framework

CVE-2026-61130 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: Oracle Commerce Platform. Vendors: Oracle.

Executive brief

Oracle Commerce Platform, a suite used for managing large-scale e-commerce operations, contains a critical vulnerability in its Dynamo Application Framework component. An unauthenticated attacker can exploit this over the network to gain full access to sensitive customer and business data. Additionally, the flaw can be used to crash the platform, leading to a complete service outage and loss of availability for the online storefront.

Technical details

A vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0 allows for remote exploitation without authentication. The flaw is accessible via HTTP and is characterized by low attack complexity, requiring no user interaction. Successful exploitation enables an attacker to gain unauthorized access to all platform-accessible data (Confidentiality impact) or trigger a repeatable crash or hang of the system (Availability impact). While the specific vulnerability class (e.g., injection or deserialization) is not explicitly named in the advisory, the impact suggests a significant compromise of the application framework's security boundaries. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Commerce Platform 11.4.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats