SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61130 2026-07-21

CVE-2026-61130: Critical Unauthenticated Flaw in Oracle Commerce Platform

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-61130, a critical (CVSS 9.1) vulnerability in Oracle Commerce Platform that lets an unauthenticated attacker seize sensitive data or crash the system over the…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-61130, a critical (CVSS 9.1) vulnerability in Oracle Commerce Platform that lets an unauthenticated attacker seize sensitive data or crash the system over the network.

What Is It

CVE-2026-61130 is a vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform. According to Oracle, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the platform. No privileges or user interaction are required (CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H), making it straightforward to trigger remotely.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.1 (CRITICAL), reflecting high impacts to both confidentiality and availability. Successful attacks can result in unauthorized access to critical data, up to complete access to all Oracle Commerce Platform accessible data, as well as the ability to cause a hang or frequently repeatable crash (complete denial of service). Because exploitation requires no authentication and only network access, exposed instances are at meaningful risk.

What's Vulnerable

The affected product is Oracle Commerce Platform, with the supported affected version listed as 11.4.0. The vulnerable component is the Dynamo Application Framework. No active exploitation has been confirmed by CISA KEV, there is no KEV entry associated with this CVE in the supplied source material.

Patch Status

Oracle addressed this issue as part of its July 2026 Critical Patch Update (CPU). Organizations running Oracle Commerce Platform 11.4.0 should apply the fixes documented in Oracle's July 2026 Critical Patch Update advisory. At time of writing, the NVD record status is "Received."

Sources