Executive brief
A security vulnerability exists in the Oracle Commerce Platform, a system used by businesses to manage online retail and customer experiences. An attacker with low-level access could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to the unauthorized disclosure of customer information or the corruption of critical platform data.
Technical details
A vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform (version 11.4.0) allows for a scope-changing attack, likely a Cross-Site Scripting (XSS) or similar injection flaw given the requirement for user interaction and the 'Scope: Changed' CVSS metric. An attacker with low privileges can exploit this over the network via HTTP. Successful exploitation requires a person other than the attacker to perform a specific action (user interaction). The impact includes unauthorized access to critical data, complete access to all platform data, and the ability to perform unauthorized updates, insertions, or deletions of some data. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Commerce Platform 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.