CVE-2026-34263: SAP SE SAP Commerce Cloud Configuration
Critical severity, CVSS 9.6. EPSS: 0.6% chance of exploitation in the next 30 days.
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.
Affected products
- SAP SE SAP Commerce Cloud Configuration: version 2211-JDK21 only
Published 2026-05-12. Last modified 2026-06-17.