CVE-2026-44761: Insecure Sample Credentials in SAP Commerce Cloud
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44761?
The severity of CVE-2026-44761 is rated as critical with a CVSS score of 9.1.
What are the risks associated with CVE-2026-44761?
The risks include exposure to unauthorized access as an attacker could exploit the sample credentials to obtain a valid access token.
How do I fix CVE-2026-44761?
To fix CVE-2026-44761, replace the sample OAuth2 client credentials with secure, custom credentials.
Who is affected by CVE-2026-44761?
Organizations using SAP Commerce Cloud that retain the default sample credentials are affected by CVE-2026-44761.
What is the impact of CVE-2026-44761?
The impact of CVE-2026-44761 allows an unauthenticated attacker to access sensitive information due to high confidentiality and integrity risks.