Executive brief
A vulnerability exists in the Oracle Commerce Platform, a suite used by businesses to manage online retail and customer experiences. An attacker with basic user access could potentially view, modify, or delete sensitive business data. While the attack is complex to execute, a successful exploit could lead to a significant loss of data integrity and confidentiality across the platform.
Technical details
A vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0 allows for unauthorized data access and modification. The flaw is exploitable by a low-privileged attacker with network access via HTTP, though the attack complexity is rated as high, suggesting specific conditions or timing are required for success. If exploited, the attacker can achieve complete read and write access to all data accessible by the Oracle Commerce Platform. The vulnerability impacts confidentiality and integrity but does not affect service availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Commerce Platform 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory