CVE-2026-44761
published 2026-07-14CVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help…
PriorityP358critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.35%
27.5th percentile
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_commerce_cloud | — | — |
| sap_se | sap_commerce_cloud | — | — |
| sap_se | sap_commerce_cloud | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP Commerce Cloud Sample Configuration information disclosure
vuldb·2026-07-14·CVSS 9.1
CVE-2026-44761 [CRITICAL] SAP Commerce Cloud Sample Configuration information disclosure
A vulnerability, which was classified as problematic, has been found in SAP Commerce Cloud. Affected by this issue is some unknown functionality of the component Sample Configuration. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2026-44761. Remote exploitation of the attack is possible. No exploit is available.
GHSA
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation.
ghsa_unreviewed·2026-07-14
CVE-2026-44761 [CRITICAL] CWE-1392 SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation.
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
No detection rules found.
No public exploits indexed.
2026-07-14
Published