Summary
CVE-2026-61129 is a critical authentication bypass vulnerability in Oracle Commerce Platform, specifically within the ATG Portals component, affecting version 11.4.0. Rated CVSS 9.8 Critical, it allows unauthenticated remote attackers to fully compromise an exposed Oracle Commerce instance over HTTP, with complete impact on confidentiality, integrity, and availability. The vulnerability was disclosed and patched as part of Oracle’s July 2026 Critical Patch Update, released on July 21, 2026.
Technical details
- Root cause: Missing authentication controls for a critical function (CWE-306) within the ATG Portals component, allowing requests to be processed without any credential verification.
- Trigger conditions: No special conditions, prior access, or configuration required; the vulnerable endpoint is reachable over standard HTTP.
- Attack vector: Network-based, unauthenticated; exploitable by any remote attacker with HTTP access to the target instance. Attack complexity is low and no user interaction is required.
- Impact: Complete compromise of the Oracle Commerce Platform — attackers can perform unauthorized creation, deletion, or modification of critical data, as well as access all data accessible by the platform, resulting in high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Commerce Platform 11.4.0 (ATG Portals component)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action: Apply the patch provided in Oracle’s July 2026 Critical Patch Update (released July 21, 2026). Refer to Oracle’s patch availability documentation accessible through the Oracle support portal.
- Network mitigation (if patching is not immediately possible): Restrict HTTP access to Oracle Commerce Platform instances at the network perimeter. Limit exposure to trusted IP ranges only and ensure internet-facing instances are placed behind a web application firewall with rules blocking unauthenticated access to ATG Portals endpoints.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

