PT-2026-57942 · Sap · Sap Commerce Cloud

CVE-2026-44761

·

Published

2026-07-14

·

Updated

2026-08-11

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Commerce Cloud (affected versions not specified)
Description SAP Commerce Cloud may retain a sample OAuth2 client with publicly documented credentials derived from sample configurations in the SAP Help Portal. An unauthenticated attacker can use these well-known credentials to obtain a valid access token and invoke specific APIs to read and modify data, leading to a high impact on confidentiality and integrity.
Recommendations Check and remove the default sample OAuth2 credentials immediately.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09908
CVE-2026-44761

Affected Products

Sap Commerce Cloud