Executive brief
Oracle Commerce Platform, a suite used by businesses to manage online retail and customer experiences, contains a critical vulnerability in its Dynamo Application Framework. An unauthorized person can use this flaw over the internet to gain full control of the platform. This could lead to the theft of customer data, disruption of online sales, and complete compromise of the commerce environment.
Technical details
A critical vulnerability exists in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0. The flaw is categorized as easily exploitable and requires no authentication or user interaction. An attacker can exploit this vulnerability remotely over HTTP to achieve a complete takeover of the affected platform, impacting confidentiality, integrity, and availability. While the specific CWE is not provided in the advisory, the CVSS score of 9.8 and the 'takeover' description suggest a high-impact flaw such as remote code execution or a complete authentication bypass. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Commerce Platform 11.4.0
Timeline
- 2026-07-21: disclosed: Published via Oracle Critical Patch Update and NVD