CVE-2026-44761

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Configurations

No configuration.

History

14 Jul 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 01:16

Updated : 2026-07-15 05:16


NVD link : CVE-2026-44761

Mitre link : CVE-2026-44761

CVE.ORG link : CVE-2026-44761


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials