CVE-2026-44761

CRITICAL

Insecure Sample Credentials in SAP Commerce Cloud

Title source: cna
STIX 2.1

Description

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

Scores

CVSS v3 9.1
EPSS 0.0046
EPSS Percentile 37.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (3)
SAP_SE/SAP Commerce Cloud 2211-JDK21
SAP_SE/SAP Commerce Cloud COM_CLOUD 2211
SAP_SE/SAP Commerce Cloud HY_COM 2205
Published Jul 14, 2026
Tracked Since Jul 14, 2026