SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-44761

CRITICAL · CVSS 9.1 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

SAP Commerce Cloud is vulnerable due to the retention of a sample OAuth2 client with publicly documented credentials, which can be exploited by unauthenticated attackers. This allows attackers to obtain valid access tokens, enabling them to read and modify sensitive data, thereby severely compromising confidentiality and integrity. Organizations using SAP Commerce Cloud should prioritize remediation to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44761
Severity
CRITICAL
CVSS
9.1
EPSS
0.46%

Original NVD Description

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.