AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-24321

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-24321
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)