Home

Description

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

PUBLISHED Reserved 2026-03-26 | Published 2026-05-12 | Updated 2026-05-15 | Assigner sap




CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-459: Incomplete Cleanup

Product status

Default status
unaffected

HY_COM 2205
affected

COM_CLOUD 2211
affected

2211-JDK21
affected

References

me.sap.com/notes/3733064

url.sap/sapsecuritypatchday

cve.org (CVE-2026-34263)

nvd.nist.gov (CVE-2026-34263)

Download JSON