SAP Commerce Cloud exposes multiple API endpoints to...
Moderate severity
Unreviewed
Published
Feb 10, 2026
to the GitHub Advisory Database
•
Updated Feb 10, 2026
Description
Published by the National Vulnerability Database
Feb 10, 2026
Published to the GitHub Advisory Database
Feb 10, 2026
Last updated
Feb 10, 2026
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.
References