Summary
CVE-2026-61133 is a high-severity information disclosure vulnerability in Oracle Commerce Platform version 11.4.0, affecting the Dynamo Application Framework component. Disclosed as part of Oracle’s July 2026 Critical Patch Update (published July 21, 2026), the flaw allows an unauthenticated remote attacker with network access via LDAP to gain unauthorized read access to all data accessible by the Oracle Commerce Platform, with a CVSS v3.1 base score of 7.5. Oracle’s own advisory characterizes this as an "easily exploitable" vulnerability requiring no credentials or user interaction.
Technical details
- Root cause: Exposure of sensitive information to an unauthorized actor (CWE-200) within the Dynamo Application Framework’s LDAP-accessible interface.
- Trigger conditions: An unauthenticated attacker requires only network-level access to the LDAP service; no credentials, elevated privileges, or user interaction are needed.
- Attack vector: Network via LDAP protocol; Attack Complexity is Low, with no authentication (PR:N) and no user interaction (UI:N) required.
- Impact: Successful exploitation grants complete read access to all data accessible by the Oracle Commerce Platform — which for enterprise deployments typically includes customer PII, order records, and other sensitive e-commerce data. There is no associated integrity or availability impact (C:H / I:N / A:N).
Affected software
- Oracle Commerce Platform version 11.4.0
Severity
CVSS v3.1 Base Score: 7.5 (High)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the patch provided in Oracle’s July 2026 Critical Patch Update. Patch details are available through Oracle Support (document ID CPU274).
- Network mitigation: If immediate patching is not possible, restrict network-level access to the Oracle Commerce Platform’s LDAP service (ports 389/636) to trusted internal networks only. Verify that this service is not inadvertently exposed to the public internet, as exposure significantly increases the risk of exploitation.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

