VDB

CVE-2026-44761

CVE-2026-44761 PUBLISHED CVSS 9.1 CRITICAL

Reported by sap · Published July 14, 2026

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
SAP_SESAP Commerce CloudHY_COM 2205, COM_CLOUD 2211, 2211-JDK21
SAP_SESAP Commerce CloudHY_COM 2205, COM_CLOUD 2211, 2211-JDK21

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›