PT-2026-39922 · Sap Se · Sap Commerce Cloud Configuration

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-34263

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-34263

Affected Products

Sap Commerce Cloud Configuration