SAPCVE-2026-44761
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1CVE-2026-44761 · Published Jul 14, 2026 · updated Jul 15, 2026
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP Commerce Cloud Product | <= HY_COM 2205 | No fix yet |
| <= COM_CLOUD 2211 | No fix yet | |
| <= 2211-JDK21 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1392
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP @ui5/webcomponents-base: clickjacking | Medium6.1 | No fix yet |
| Jul 14 | SAP CRM (WebClient UI): attacker could inject | Medium4.1 | No fix yet |
| Jul 14 | SAP S/4HANA Project Management (PPM-PRO): SQL injection | Medium5.5 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP S/4HANA (Draft operation): privilege escalation | Medium4.3 | No fix yet |
| Jul 14 | SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization | High7.6 | No fix yet |