CRITICAL
9.8 CVE-2026-70954 Published 18 Aug 2026
Oracle Commerce Platform Unauthenticated Takeover Vulnerability
Worried this affects one of your servers?
Vulnerability in Oracle Commerce Platform (component: Dynamo Application Framework) allows an unauthenticated attacker with network access via HTTP to compromise the platform. The flaw can result in takeover of Oracle Commerce Platform.
Affected versions and impact:
- Supported version affected: 11.4.0
- Attack vector: network via HTTP, no authentication required
- Impact: full takeover with high confidentiality, integrity, and availability impacts
- CVSS 3.1 Base Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Reference: CVE-2026-70954 on NVD
← Back to Security News