CVE-2026-24321
SAP Commerce Cloud Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-24321 is an information disclosure vulnerability in SAP Commerce Cloud that exposes multiple API endpoints to unauthenticated users, allowing retrieval of sensitive information not intended to be publicly accessible. It affects SAP Commerce Cloud versions 2205 and 2211. The vulnerability was published on February 10, 2026, with a patch made available on SAP Security Patch Day in February 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (SAP Security Notes, Red Hat CVE).

Détails techniques

The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). SAP Commerce Cloud fails to enforce authentication on multiple API endpoints, allowing any network-accessible user to submit requests and receive sensitive data that should be restricted to authenticated front-end users. The attack requires no privileges, no user interaction, and is exploitable remotely over the network with low complexity. No public proof-of-concept code has been identified (SAP Security Notes, Onapsis Blog).

Impact

Successful exploitation results in unauthorized access to sensitive information through unauthenticated API requests, with a low confidentiality impact. There is no impact to the integrity or availability of the affected system. The exposed data may include private personal information not intended for public access, posing a risk of data exposure for customers or users of SAP Commerce Cloud deployments (Red Hat CVE, SAP Security Notes).

Exploitabilité

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. A vendor patch is available (Onapsis Blog, Red Hat CVE).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing SAP Commerce Cloud instances running versions 2205 or 2211 using passive reconnaissance tools (e.g., Shodan, Censys) or by reviewing publicly accessible URLs.
  2. Enumerate API endpoints: Probe the target for known SAP Commerce Cloud API endpoints that may be exposed without authentication (e.g., OCC REST API endpoints).
  3. Submit unauthenticated requests: Send HTTP GET or POST requests to the identified open endpoints without providing any authentication credentials or session tokens.
  4. Retrieve sensitive information: Collect the sensitive data returned in the API responses, which may include private personal information not intended for public access (SAP Security Notes, Onapsis Blog).

Indicateurs de compromis

  • Network: Unusual or high-volume unauthenticated HTTP requests to SAP Commerce Cloud API endpoints (e.g., /occ/v2/ paths) from external or unexpected IP addresses.
  • Logs: SAP Commerce Cloud access logs showing repeated API calls without authentication tokens or session identifiers, particularly to endpoints returning customer or order data.
  • Logs: Anomalous patterns of API access outside of normal business hours or from geographically unexpected sources targeting sensitive data endpoints.

Atténuation et solutions de contournement

SAP has released a patch as part of SAP Security Patch Day in February 2026; organizations should apply the available security note to affected SAP Commerce Cloud versions 2205 and 2211 immediately (SAP Security Notes). As interim workarounds, administrators should review and restrict access to API endpoints to require authentication, and implement network-level controls (e.g., WAF rules, IP allowlisting) to limit unauthenticated access to sensitive API paths. Regularly audit API endpoint exposure as part of ongoing security hygiene (Onapsis Blog).

Réactions de la communauté

The vulnerability was covered as part of broader SAP February 2026 Patch Day reporting by security firms including Onapsis, SecurityBridge, and RedRays, which noted it as a medium-severity information disclosure issue among a larger set of SAP patches released that month (Onapsis Blog, SecurityBridge Blog, RedRays Blog). General media coverage focused primarily on higher-severity vulnerabilities in SAP CRM and SAP S/4HANA patched in the same cycle, with CVE-2026-24321 receiving limited standalone attention due to its medium severity rating.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté SAP Commerce Cloud Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-58231CRITICAL10
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NonNonAug 11, 2026
CVE-2024-33003CRITICAL9.1
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NonNonAug 13, 2024
CVE-2023-42481HIGH8.1
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NonNonDec 12, 2023
CVE-2026-23684MEDIUM5.9
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NonNonFeb 10, 2026
CVE-2026-24321MEDIUM5.3
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NonNonFeb 10, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités