CRITICAL 9.8 CVE-2026-70954 Published 18 Aug 2026

Oracle Commerce Platform Unauthenticated Takeover Vulnerability

Worried this affects one of your servers?

Vulnerability in Oracle Commerce Platform (component: Dynamo Application Framework) allows an unauthenticated attacker with network access via HTTP to compromise the platform. The flaw can result in takeover of Oracle Commerce Platform.

Affected versions and impact:

  • Supported version affected: 11.4.0
  • Attack vector: network via HTTP, no authentication required
  • Impact: full takeover with high confidentiality, integrity, and availability impacts
  • CVSS 3.1 Base Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Reference: CVE-2026-70954 on NVD

← Back to Security News