
PEACH
Un cadre d’isolation des locataires
CVE-2026-24321 is an information disclosure vulnerability in SAP Commerce Cloud that exposes multiple API endpoints to unauthenticated users, allowing retrieval of sensitive information not intended to be publicly accessible. It affects SAP Commerce Cloud versions 2205 and 2211. The vulnerability was published on February 10, 2026, with a patch made available on SAP Security Patch Day in February 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (SAP Security Notes, Red Hat CVE).
The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). SAP Commerce Cloud fails to enforce authentication on multiple API endpoints, allowing any network-accessible user to submit requests and receive sensitive data that should be restricted to authenticated front-end users. The attack requires no privileges, no user interaction, and is exploitable remotely over the network with low complexity. No public proof-of-concept code has been identified (SAP Security Notes, Onapsis Blog).
Successful exploitation results in unauthorized access to sensitive information through unauthenticated API requests, with a low confidentiality impact. There is no impact to the integrity or availability of the affected system. The exposed data may include private personal information not intended for public access, posing a risk of data exposure for customers or users of SAP Commerce Cloud deployments (Red Hat CVE, SAP Security Notes).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. A vendor patch is available (Onapsis Blog, Red Hat CVE).
/occ/v2/ paths) from external or unexpected IP addresses.SAP has released a patch as part of SAP Security Patch Day in February 2026; organizations should apply the available security note to affected SAP Commerce Cloud versions 2205 and 2211 immediately (SAP Security Notes). As interim workarounds, administrators should review and restrict access to API endpoints to require authentication, and implement network-level controls (e.g., WAF rules, IP allowlisting) to limit unauthenticated access to sensitive API paths. Regularly audit API endpoint exposure as part of ongoing security hygiene (Onapsis Blog).
The vulnerability was covered as part of broader SAP February 2026 Patch Day reporting by security firms including Onapsis, SecurityBridge, and RedRays, which noted it as a medium-severity information disclosure issue among a larger set of SAP patches released that month (Onapsis Blog, SecurityBridge Blog, RedRays Blog). General media coverage focused primarily on higher-severity vulnerabilities in SAP CRM and SAP S/4HANA patched in the same cycle, with CVE-2026-24321 receiving limited standalone attention due to its medium severity rating.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."