
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24321 is an information disclosure vulnerability in SAP Commerce Cloud that exposes multiple API endpoints to unauthenticated users, allowing retrieval of sensitive information not intended to be publicly accessible. It affects SAP Commerce Cloud versions 2205 and 2211. The vulnerability was published on February 10, 2026, with a patch made available on SAP Security Patch Day in February 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (SAP Security Notes, Red Hat CVE).
The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). SAP Commerce Cloud fails to enforce authentication on multiple API endpoints, allowing any network-accessible user to submit requests and receive sensitive data that should be restricted to authenticated front-end users. The attack requires no privileges, no user interaction, and is exploitable remotely over the network with low complexity. No public proof-of-concept code has been identified (SAP Security Notes, Onapsis Blog).
Successful exploitation results in unauthorized access to sensitive information through unauthenticated API requests, with a low confidentiality impact. There is no impact to the integrity or availability of the affected system. The exposed data may include private personal information not intended for public access, posing a risk of data exposure for customers or users of SAP Commerce Cloud deployments (Red Hat CVE, SAP Security Notes).
/occ/v2/ paths) from external or unexpected IP addresses.SAP has released a patch as part of SAP Security Patch Day in February 2026; organizations should apply the available security note to affected SAP Commerce Cloud versions 2205 and 2211 immediately (SAP Security Notes). As interim workarounds, administrators should review and restrict access to API endpoints to require authentication, and implement network-level controls (e.g., WAF rules, IP allowlisting) to limit unauthenticated access to sensitive API paths. Regularly audit API endpoint exposure as part of ongoing security hygiene (Onapsis Blog).
The vulnerability was covered as part of broader SAP February 2026 Patch Day reporting by security firms including Onapsis, SecurityBridge, and RedRays, which noted it as a medium-severity information disclosure issue among a larger set of SAP patches released that month (Onapsis Blog, SecurityBridge Blog, RedRays Blog). General media coverage focused primarily on higher-severity vulnerabilities in SAP CRM and SAP S/4HANA patched in the same cycle, with CVE-2026-24321 receiving limited standalone attention due to its medium severity rating.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."