CVE-2026-76969: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Multitenant SAP Cloud Application Programming Model applications that use the @sap/cds-mtxs NPM library and have extensibility enabled are identified as affected.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction.
What could an attacker do after successful exploitation?
An attacker may obtain sensitive credentials and abuse them to replace or delete tenant data. This can cause high integrity and availability impact, with a possible partial confidentiality impact on business data.