Oracle's July 2026 Critical Patch Update discloses CVE-2026-61130, a critical (CVSS 9.1) vulnerability in Oracle Commerce Platform that lets an unauthenticated attacker seize sensitive data or crash the system over the network.
What Is It
CVE-2026-61130 is a vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform. According to Oracle, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the platform. No privileges or user interaction are required (CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H), making it straightforward to trigger remotely.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.1 (CRITICAL), reflecting high impacts to both confidentiality and availability. Successful attacks can result in unauthorized access to critical data, up to complete access to all Oracle Commerce Platform accessible data, as well as the ability to cause a hang or frequently repeatable crash (complete denial of service). Because exploitation requires no authentication and only network access, exposed instances are at meaningful risk.
What's Vulnerable
The affected product is Oracle Commerce Platform, with the supported affected version listed as 11.4.0. The vulnerable component is the Dynamo Application Framework. No active exploitation has been confirmed by CISA KEV, there is no KEV entry associated with this CVE in the supplied source material.
Patch Status
Oracle addressed this issue as part of its July 2026 Critical Patch Update (CPU). Organizations running Oracle Commerce Platform 11.4.0 should apply the fixes documented in Oracle's July 2026 Critical Patch Update advisory. At time of writing, the NVD record status is "Received."