Description
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Published: 2026-07-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SAP Commerce Cloud deployment may retain a sample OAuth2 client that contains publicly documented credentials provided in sample configuration documents. An unauthenticated attacker can use these well‑known credentials to acquire a valid access token and then invoke certain APIs to read and modify protected data. The weakness corresponds to misconfiguration (CWE‑1392) and results in a high‑impact compromise of confidentiality and integrity with no effect on availability.

Affected Systems

Any SAP Commerce Cloud installation that has not removed or updated the built‑in sample OAuth2 client configuration is susceptible. The advisory does not list specific product versions, so all releases that still ship this default client when left untouched are at risk.

Risk and Exploitability

The CVSS score of 9.1 classifies the issue as critical, and the EPSS score of < 1 % indicates that exploitation activity is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an adversary with network access to the OAuth2 authorization endpoint; once the default client is used, the token acquisition process is trivial and requires no additional privileges, allowing the attacker to compromise sensitive data within the Commerce application.

Generated by OpenCVE AI on July 31, 2026 at 10:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SAP SE SAP Commerce patch referenced in Advisory Note 3753495 to eliminate the default sample credentials.
  • Remove or replace any remaining default OAuth2 client configuration with unique, secure credentials.
  • If a patch is not immediately available, temporarily disable or restrict access to the OAuth2 authentication endpoint or block the use of the sample credentials at the network level.
  • Continuously monitor authentication logs for attempts to use the default sample credentials.

Generated by OpenCVE AI on July 31, 2026 at 10:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Title Insecure Sample Credentials in SAP Commerce Cloud
Weaknesses CWE-1392
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-07-15T03:58:51.555Z

Reserved: 2026-05-07T18:31:04.067Z

Link: CVE-2026-44761

cve-icon Vulnrichment

Updated: 2026-07-14T12:49:10.679Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:00:06Z

Weaknesses