← Back

CVE-2026-24321

nvd nist
Published: Feb 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: CNA (Secondary)

Description

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

Affected (2)

Products: Sap: Commerce Cloud
1 product
Commerce Cloud
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 2205
Version 2211

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.