PT-2026-57942 · Sap · Sap Commerce Cloud
CVE-2026-44761
·
Published
2026-07-14
·
Updated
2026-08-11
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Commerce Cloud (affected versions not specified)
Description
SAP Commerce Cloud may retain a sample OAuth2 client with publicly documented credentials derived from sample configurations in the SAP Help Portal. An unauthenticated attacker can use these well-known credentials to obtain a valid access token and invoke specific APIs to read and modify data, leading to a high impact on confidentiality and integrity.
Recommendations
Check and remove the default sample OAuth2 credentials immediately.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Commerce Cloud