Executive brief
SAP Commerce Cloud, a platform used for managing large-scale e-commerce operations, contains a critical security flaw due to misconfigured security settings. An unauthenticated attacker can remotely upload malicious configurations and inject code into the system. If exploited, this allows the attacker to take full control of the application, potentially leading to the theft of customer data, disruption of online sales, and complete compromise of the business environment.
Technical details
A critical vulnerability exists in SAP Commerce Cloud due to an improper Spring Security configuration. This flaw allows an unauthenticated remote attacker to perform malicious configuration uploads and input injection. The root cause is a failure to properly restrict access to sensitive configuration endpoints, leading to arbitrary server-side code execution (RCE). An exploit can result in a total compromise of confidentiality, integrity, and availability. SAP has released security note 3733064 to address this issue as part of their May 2026 Patch Day.
Affected products
- SAP Commerce Cloud
Timeline
- 2026-05-12: advisory: SAP published security note 3733064 during the May Patch Day.
- 2026-05-12: disclosed: CVE-2026-34263 was published to the NVD.