SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
References
Configurations
No configuration.
History
14 Jul 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 01:16
Updated : 2026-07-15 05:16
NVD link : CVE-2026-44761
Mitre link : CVE-2026-44761
CVE.ORG link : CVE-2026-44761
JSON object : View
Products Affected
No product.
CWE
CWE-1392
Use of Default Credentials
