VDB
CVE-2026-44761
CVE-2026-44761
PUBLISHED
CVSS 9.1 CRITICAL
Reported by sap · Published July 14, 2026
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Commerce Cloud | HY_COM 2205, COM_CLOUD 2211, 2211-JDK21 |
| SAP_SE | SAP Commerce Cloud | HY_COM 2205, COM_CLOUD 2211, 2211-JDK21 |
Timeline
- Jul 14, 2026 EPSS Score
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published