
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23684 is a race condition vulnerability in SAP Commerce Cloud that allows unauthenticated remote attackers to manipulate cart entries during the checkout process. When an attacker concurrently adds products to a cart, the race condition may result in a cart entry being created with an erroneous product value that can subsequently be checked out, leading to fraudulent transactions. Affected versions include SAP Commerce Cloud 2205 and 2211. It carries a CVSS v3.1 base score of 5.9 (Medium), with high integrity impact and no confidentiality or availability impact (Red Hat CVE, SAP Security Notes).
The vulnerability is classified under CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization) and CWE-366 (Race Condition within a Thread), indicating insufficient synchronization controls around cart management operations in SAP Commerce Cloud. An unauthenticated network attacker can exploit this by sending concurrent requests to add products to a cart, exploiting a time-of-check/time-of-use (TOCTOU) window (CAPEC-29) to cause a cart entry to be persisted with an incorrect product value. No authentication or user interaction is required, but the high attack complexity rating reflects the need to win a timing race. No public proof-of-concept code has been identified (Red Hat CVE, Onapsis Blog).
Successful exploitation allows an attacker to complete fraudulent e-commerce transactions by checking out cart entries with manipulated or erroneous product values, directly compromising data integrity. This could result in significant financial losses for merchants through fraudulent purchases at incorrect prices or with substituted products. There is no impact on data confidentiality or application availability (Red Hat CVE, Onapsis Blog).
/cart/add, cart entry creation APIs) from a single IP or small IP range within a short time window.SAP released patches for CVE-2026-23684 as part of the February 2026 SAP Security Patch Day; organizations should apply the relevant SAP Security Notes for Commerce Cloud versions 2205 and 2211 via the SAP Support Portal. Until patching is complete, administrators should implement rate limiting on cart operation endpoints, add server-side cart integrity validation checks, and enable enhanced logging and alerting for unusual cart modification patterns. Monitoring for concurrent cart requests from the same session and implementing transaction-level locking on cart entries are recommended interim controls (SAP Security Notes, Onapsis Blog).
The vulnerability was covered as part of SAP's February 2026 Patch Day roundups by several SAP security specialists. Onapsis and SecurityBridge both published patch day summaries highlighting the race condition in SAP Commerce Cloud among the month's notable fixes. RedRays also covered the February 2026 SAP patch day. General community sentiment treats this as a medium-severity business logic flaw with limited immediate exploitation risk due to the high attack complexity (Onapsis Blog, SecurityBridge Blog, RedRays Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."