Insufficient Validation in SAP's Multitenant CAP Application Library
CVE-2026-76969

9.4CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76969?

The @sap/cds-mtxs library, utilized in SAP's multitenant Cloud Application Programming (CAP) model, lacks adequate checks for certain functionalities related to extensibility. This weakness permits unauthenticated attackers to exploit the library's features by sending malformed requests, potentially gaining access to sensitive credentials. As a consequence, they may manipulate, replace, or delete tenant data, significantly impacting the availability and integrity of applications relying on these services. Furthermore, this issue raises concerns regarding the confidentiality of essential business data.

Affected Version(s)

SAP Cloud Application Programming Model (CAP) @sap/cds-mtxs <=1.18.3 <= @sap/cds-mtxs 1.18.3

SAP Cloud Application Programming Model (CAP) <=2.7.6 <= 2.7.6

SAP Cloud Application Programming Model (CAP) <=3.9.6 <= 3.9.6

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.