CVE-2026-24321: Information Disclosure vulnerability in SAP Commerce Cloud
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24321?
CVE-2026-24321 is classified as an information disclosure vulnerability with a critical severity level due to the potential exposure of sensitive information.
How do I fix CVE-2026-24321?
To remediate CVE-2026-24321, implement authentication and access controls on the exposed API endpoints to restrict unauthorized access.
What information is exposed by CVE-2026-24321?
CVE-2026-24321 allows unauthenticated users to access sensitive information through multiple open API endpoints meant for internal use only.
Which versions of SAP Commerce Cloud are affected by CVE-2026-24321?
CVE-2026-24321 affects multiple versions of SAP Commerce Cloud that expose sensitive API endpoints without proper authentication.
What are the potential risks of CVE-2026-24321?
The potential risks of CVE-2026-24321 include unauthorized data access, leakage of sensitive information, and increased likelihood of further exploitation.