OAuth2 Client Vulnerability in SAP Commerce Cloud

⚠️ CVE-Referenzen: CVE-2026-44761
SAP - SAP Commerce Cloud - CRITICAL - CVE-2026-44761. SAP Commerce Cloud contains a vulnerability where a sample OAuth2 client, equipped with publicly available credentials from the SAP Help Portal documentation, may remain unchanged. This presents a significant security risk, as an unauthenticated attacker could utilize these predictable credentials to gain valid access tokens. Once obtained, the attacker can invoke certain APIs, potentially compromising confidentiality and integrity by accessing and altering sensitive data. Immediate attention to the configuration and management of these credentials is essential to prevent unauthorized access.
Quelle: securityvulnerability.io