OAuth2 Client Vulnerability in SAP Commerce Cloud
CVE-2026-44761
Key Information:
- Vendor
SAP
- Status
- Vendor
- CVE Published:
- 14 July 2026
Badges
What is CVE-2026-44761?
SAP Commerce Cloud contains a vulnerability where a sample OAuth2 client, equipped with publicly available credentials from the SAP Help Portal documentation, may remain unchanged. This presents a significant security risk, as an unauthenticated attacker could utilize these predictable credentials to gain valid access tokens. Once obtained, the attacker can invoke certain APIs, potentially compromising confidentiality and integrity by accessing and altering sensitive data. Immediate attention to the configuration and management of these credentials is essential to prevent unauthorized access.
Affected Version(s)
SAP Commerce Cloud HY_COM 2205
SAP Commerce Cloud COM_CLOUD 2211
SAP Commerce Cloud 2211-JDK21
News Articles
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP patches three critical flaws, including a 9.9 NetWeaver ABAP memory bug and default OAuth credentials that may expose Commerce Cloud data.
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved