GHSA-686g-q5w6-7j38CriticalCVSS 10.0

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

🔗 References (4)