Executive brief
SAP Commerce Cloud, an e-commerce platform, may contain default administrative credentials if sample configurations from official documentation were used during setup. An unauthorized attacker could use these publicly known credentials to gain access to the system. This would allow them to view or modify sensitive business and customer data, potentially leading to significant data breaches or unauthorized changes to the online store.
Technical details
SAP Commerce Cloud is vulnerable to the use of default credentials (CWE-1392) when sample configurations provided in the SAP Help Portal are retained in production environments. The vulnerability stems from a sample OAuth2 client that uses well-known, publicly documented credentials. A remote, unauthenticated attacker can use these credentials to obtain a valid access token via the OAuth2 flow. With this token, the attacker can invoke specific APIs to read and modify sensitive data. The exploitability is high due to the lack of required authentication or user interaction, though it does not impact service availability. Affected versions include HY_COM 2205 and COM_CLOUD 2211.
Affected products
- SAP SE Commerce Cloud HY_COM 2205, COM_CLOUD 2211, 2211-JDK21
Timeline
- 2026-07-14: advisory: Published as part of SAP Security Patch Day July 2026