A critical, unauthenticated flaw in Oracle Commerce Platform 11.4.0 lets a remote attacker fully compromise the system over HTTP, carrying a maximum-tier CVSS score of 9.8.
What Is It
CVE-2026-61131 is a critical vulnerability in the Oracle Commerce Platform product, specifically within the Dynamo Application Framework component. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the platform. A successful attack can result in complete takeover of Oracle Commerce Platform. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning no authentication, no user interaction, and low attack complexity, with high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network-reachable exposure, no privileges required, and full compromise makes this among the most severe vulnerability classes. An attacker who reaches an affected instance over HTTP can take it over outright, threatening the confidentiality, integrity, and availability of the commerce environment and any data it processes. There is no active-exploitation confirmation in the supplied data: the CISA KEV entry is empty, so this is not currently listed as a Known Exploited Vulnerability. The critical score alone, however, warrants urgent attention.
What's Vulnerable
Per the NVD record, the affected product is Oracle Commerce Platform (vendor: Oracle Corporation), component Dynamo Application Framework. The supported version listed as affected is 11.4.0.
Patch Status
Oracle addresses this issue in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the corresponding fixes for affected Oracle Commerce Platform 11.4.0 deployments. No additional remediation details are provided in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61131, https://nvd.nist.gov/vuln/detail/CVE-2026-61131