SAP Commerce Cloud Unauthenticated API Access Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability exists in SAP Commerce Cloud, where multiple API endpoints are exposed to unauthenticated users. This allows them to send requests to these open endpoints and retrieve sensitive information that should not be publicly accessible through the front-end. The vulnerability has a low impact on confidentiality and does not affect integrity or availability.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information via the exposed API endpoints.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.

Added: Feb 10, 2026, 6:14 AM
Updated: Feb 10, 2026, 6:14 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.7
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.