← Back

CVE-2026-23684

nvd nist
Published: Feb 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: CNA (Secondary)

Description

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

Affected (2)

Products: Sap: Commerce Cloud
1 product
Commerce Cloud
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 2205
Version 2211

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.