A critical (CVSS 9.8) flaw in Oracle Commerce Platform's ATG Portals component lets an unauthenticated attacker take over the system over the network.
What Is It
CVE-2026-61129 is a critical vulnerability in the Oracle Commerce Platform product of Oracle Commerce, in the ATG Portals component. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the platform. Successful exploitation can result in a full takeover of Oracle Commerce Platform. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, low attack complexity, no required privileges, and no user interaction means this vulnerability can be exploited remotely by an anonymous attacker without any authentication. Because successful attacks result in complete takeover of the platform, with high impact across confidentiality, integrity, and availability, the risk to affected e-commerce deployments is severe.
What's Vulnerable
The affected product is Oracle Commerce Platform (vendor: Oracle Corporation), specifically the ATG Portals component. The supported version confirmed as affected is 11.4.0.
Patch Status
Oracle addressed this issue in its Critical Patch Update advisory dated July 2026. Affected organizations should apply the fixes referenced in Oracle's July 2026 Critical Patch Update. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61129, https://nvd.nist.gov/vuln/detail/CVE-2026-61129