Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 15 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. |
Tue, 12 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap Se
Sap Se sap Commerce Cloud Configuration |
|
| Vendors & Products |
Sap Se
Sap Se sap Commerce Cloud Configuration |
Tue, 12 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. | |
| Title | Missing authentication check in SAP Commerce cloud configuration | |
| Weaknesses | CWE-459 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-05-15T11:47:04.699Z
Reserved: 2026-03-26T19:02:45.983Z
Link: CVE-2026-34263
Updated: 2026-05-12T13:36:35.410Z
Status : Awaiting Analysis
Published: 2026-05-12T03:16:11.650
Modified: 2026-05-15T12:17:07.750
Link: CVE-2026-34263
No data.
OpenCVE Enrichment
Updated: 2026-05-15T14:30:46Z