Executive brief
The SAP Cloud Application Programming Model (CAP) cds-mtxs library is used to build multitenant cloud applications. An unauthenticated attacker can exploit insufficient validation checks to steal authentication credentials and use them to alter or delete customer data across multiple tenants, compromising both data integrity and availability.
Technical details
The @sap/cds-mtxs NPM library fails to perform sufficient authorization checks on extensibility functionality in multitenant CAP applications (CWE-522: Insufficiently Protected Credentials). Unauthenticated attackers can craft requests to expose sensitive credentials without requiring authentication or user interaction, then abuse those credentials to modify or delete tenant data. The vulnerability affects versions >= 4.0.1 < 4.0.3, >= 3.0.1 < 3.9.7, >= 2.0.2 < 2.7.7, and < 1.18.4. Patches are available in versions 4.0.3, 3.9.7, 2.7.7, and 1.18.4 respectively.
Affected products
- SAP cds-mtxs versions 4.0.1 to 4.0.2, 3.0.1 to 3.9.6, 2.0.2 to 2.7.6, and all versions before 1.18.4
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Patches released in versions 4.0.3, 3.9.7, 2.7.7, and 1.18.4