SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-76969

CRITICAL · CVSS 9.4 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The @sap/cds-mtxs NPM library is vulnerable due to inadequate checks in its multitenant capabilities, allowing unauthenticated attackers to send crafted requests that can expose sensitive credentials. This could lead to unauthorized modifications or deletions of tenant data, significantly impacting the application's availability and integrity, while also posing a risk to the confidentiality of business data. Organizations utilizing this library, particularly those with multitenant CAP applications and extensibility enabled, should prioritize immediate remediation efforts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76969
Severity
CRITICAL
CVSS
9.4
EPSS
0.29%

Original NVD Description

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.