Insufficient Validation in SAP's Multitenant CAP Application Library
CVE-2026-76969
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-76969?
The @sap/cds-mtxs library, utilized in SAP's multitenant Cloud Application Programming (CAP) model, lacks adequate checks for certain functionalities related to extensibility. This weakness permits unauthenticated attackers to exploit the library's features by sending malformed requests, potentially gaining access to sensitive credentials. As a consequence, they may manipulate, replace, or delete tenant data, significantly impacting the availability and integrity of applications relying on these services. Furthermore, this issue raises concerns regarding the confidentiality of essential business data.
Affected Version(s)
SAP Cloud Application Programming Model (CAP) @sap/cds-mtxs <=1.18.3 <= @sap/cds-mtxs 1.18.3
SAP Cloud Application Programming Model (CAP) <=2.7.6 <= 2.7.6
SAP Cloud Application Programming Model (CAP) <=3.9.6 <= 3.9.6