Summary
CVE-2026-70954 is a critical, easily exploitable vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0. It allows an unauthenticated attacker with network access via HTTP to fully compromise the platform, with Oracle stating that successful exploitation can result in complete takeover of the system. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The vulnerability resides in the Dynamo Application Framework component underlying Oracle Commerce Platform 11.4.0.
- Trigger conditions: No authentication or user interaction is required to exploit the flaw.
- Attack vector: Remote exploitation over HTTP/network access (AV:N), with low attack complexity (AC:L) and no privileges required (PR:N).
- Impact: Successful exploitation results in high impact to confidentiality, integrity, and availability — Oracle describes the outcome as a full "takeover" of Oracle Commerce Platform.
Affected software
- Oracle Commerce Platform, version 11.4.0 (Dynamo Application Framework component)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update for Oracle Commerce Platform 11.4.0. Organizations should treat this as urgent given the unauthenticated, network-exploitable nature of the flaw.
- If patching cannot be applied immediately: Restrict network access to Oracle Commerce Platform instances (e.g., limit exposure to trusted networks, place behind a WAF/reverse proxy, and monitor for anomalous HTTP requests) until the vendor patch can be deployed, then apply the patch as soon as possible — no other Oracle-endorsed workaround is documented.

