CVE-2026-23684

MEDIUM

SAP Commerce cloud - Info Disclosure

Title source: llm
STIX 2.1

Description

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

Scores

CVSS v3 5.9
EPSS 0.0003
EPSS Percentile 10.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362 CWE-366
Status published
Products (2)
sap/commerce_cloud 2205
sap/commerce_cloud 2211
Published Feb 10, 2026
Tracked Since Feb 18, 2026