Vulnerability intelligence
CVE-2026-44761
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.5%
Riskier than 39% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered Jul 14, 2026 · latest Jul 14, 2026
Tracked incidents
Coverage timeline
-
SAP patches memory corruption flaw in NetWeaver after Patch Daywww.securityweek.com · Jul 14, 2026
-
SAP July 2026 Patch Tackles NetWeaver Memory Corruption Bugsecurityonline.info · Jul 14, 2026