Missing authentication check in SAP Commerce cloud configuration
CVE-2026-34263

9.6CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34263?

Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

Affected Version(s)

SAP Commerce cloud configuration HY_COM 2205

SAP Commerce cloud configuration COM_CLOUD 2211

SAP Commerce cloud configuration 2211-JDK21

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.