ZeroHour

CVE-2026-23684

CVSS 3.1
5.9 medium
EPSS
<1%p7
Published
()
Modified
Description

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

Vendors
sap
Products
commerce cloud
Weakness
CWE-366, CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.