Skip to content
SAPCVE-2026-44761

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...

Critical9.1CVE-2026-44761 · Published Jul 14, 2026 · updated Jul 15, 2026

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP Commerce Cloud
Product
<= HY_COM 2205No fix yet
<= COM_CLOUD 2211No fix yet
<= 2211-JDK21No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1392

More SAP advisories

All SAP
Advisory
SAP @ui5/webcomponents-base: clickjacking
Medium6.1Jul 14
SAP CRM (WebClient UI): attacker could inject
Medium4.1Jul 14
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5Jul 14
SAP S/4 HANA (Create Single Payment): missing authorization
Medium4.3Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14
SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization
High7.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.