Code Injection Vulnerability in SAP Commerce Cloud
CVE-2026-34263

9.6CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34263?

SAP Commerce Cloud suffers from a vulnerability due to improper configuration in Spring Security. This flaw allows unauthenticated users to upload malicious configurations and execute arbitrary code on the server. Such exploitation significantly jeopardizes the application's confidentiality, integrity, and availability, making it essential for users to address this risk promptly.

Affected Version(s)

SAP Commerce cloud configuration HY_COM 2205

SAP Commerce cloud configuration COM_CLOUD 2211

SAP Commerce cloud configuration 2211-JDK21

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.