
PEACH
Un cadre d’isolation des locataires
CVE-2026-23684 is a race condition vulnerability in SAP Commerce Cloud that allows unauthenticated remote attackers to manipulate cart entries during the checkout process. When an attacker concurrently adds products to a cart, the race condition may result in a cart entry being created with an erroneous product value that can subsequently be checked out, leading to fraudulent transactions. Affected versions include SAP Commerce Cloud 2205 and 2211. It carries a CVSS v3.1 base score of 5.9 (Medium), with high integrity impact and no confidentiality or availability impact (Red Hat CVE, SAP Security Notes).
The vulnerability is classified under CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization) and CWE-366 (Race Condition within a Thread), indicating insufficient synchronization controls around cart management operations in SAP Commerce Cloud. An unauthenticated network attacker can exploit this by sending concurrent requests to add products to a cart, exploiting a time-of-check/time-of-use (TOCTOU) window (CAPEC-29) to cause a cart entry to be persisted with an incorrect product value. No authentication or user interaction is required, but the high attack complexity rating reflects the need to win a timing race. No public proof-of-concept code has been identified (Red Hat CVE, Onapsis Blog).
Successful exploitation allows an attacker to complete fraudulent e-commerce transactions by checking out cart entries with manipulated or erroneous product values, directly compromising data integrity. This could result in significant financial losses for merchants through fraudulent purchases at incorrect prices or with substituted products. There is no impact on data confidentiality or application availability (Red Hat CVE, Onapsis Blog).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-23684. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, reflecting a low probability of near-term exploitation. The high attack complexity (requiring a successful race condition) further limits practical exploitability (Red Hat CVE).
/cart/add, cart entry creation APIs) from a single IP or small IP range within a short time window.SAP released patches for CVE-2026-23684 as part of the February 2026 SAP Security Patch Day; organizations should apply the relevant SAP Security Notes for Commerce Cloud versions 2205 and 2211 via the SAP Support Portal. Until patching is complete, administrators should implement rate limiting on cart operation endpoints, add server-side cart integrity validation checks, and enable enhanced logging and alerting for unusual cart modification patterns. Monitoring for concurrent cart requests from the same session and implementing transaction-level locking on cart entries are recommended interim controls (SAP Security Notes, Onapsis Blog).
The vulnerability was covered as part of SAP's February 2026 Patch Day roundups by several SAP security specialists. Onapsis and SecurityBridge both published patch day summaries highlighting the race condition in SAP Commerce Cloud among the month's notable fixes. RedRays also covered the February 2026 SAP patch day. General community sentiment treats this as a medium-severity business logic flaw with limited immediate exploitation risk due to the high attack complexity (Onapsis Blog, SecurityBridge Blog, RedRays Blog).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."