SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-46421

CRITICAL · CVSS 9.3 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The compromised versions of `@cap-js/sqlite`, `@cap-js/postgres`, and `@cap-js/db-service` in the SAP Cloud Application Programming Model are vulnerable to credential harvesting and self-propagation. Users who have installed these specific versions should prioritize upgrading to the latest secure releases and immediately rotate any exposed credentials, including npm tokens and GitHub personal access tokens. Organizations utilizing these packages for cloud application development must act swiftly to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-46421
Severity
CRITICAL
CVSS
9.3
EPSS
0.38%
GitHub

Original NVD Description

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised. User should upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials. No known workarounds are available.