CVE-2026-44761

SAP Commerce Cloud könnte ein Beispiel-OAuth2-Client mit öffentlich dokumentierten Beispielanmeldeinformationen beibehalten, die aus eine…

criticalEPSS 0.5%

Description

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

Metrics

9.1
Source: nvd-v3
40.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-14 00:20 UTC
CWE-1392

Weakness classes (CWE)

  • CWE-1392Base

    Use of Default Credentials

    The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

    cwe.mitre.org →

References & sources

Linked advisories