Summary
SAP Commerce Cloud's configuration handling is misconfigured with Spring Security, allowing an unauthenticated attacker to upload malicious configuration and inject code. The vulnerable flow sits in the Commerce Cloud configuration path and does not require valid credentials. Successful exploitation leads to arbitrary server-side code execution in the application context, with high impact to confidentiality, integrity, and availability.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary server-side code in the SAP Commerce Cloud application context
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| SAP Commerce Cloud | HY_COM 2205, COM_CLOUD 2211, 2211-JDK21 |
SAP Commerce Cloud is SAP's cloud e-commerce platform for storefronts, product catalogs, pricing, checkout, and order management.
Affected ComponentCommerce Cloud configuration upload flow and the Spring Security authentication check protecting that flow.
Commerce Cloud configuration upload flow and the Spring Security authentication check protecting that flow.
Not available
Apply SAP Note 3733064 from the May 12, 2026 SAP Security Patch Day to the affected SAP Commerce Cloud builds (HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21).
Apply SAP Note 3733064 from the May 12, 2026 SAP Security Patch Day to the affected SAP Commerce Cloud builds (HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21).
Not available
Probability of exploitation in the next 30 days
Worse than 7% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| support.sap.com | SAP Security Patch Day - May 2026 |
| nvd.nist.gov | CVE-2026-34263 Detail |
| me.sap.com | SAP Note 3733064 |
| help.sap.com | SAP Commerce Cloud in the Public Cloud |
| tenable.com | CVE-2026-34263 |
| bleepingcomputer.com | SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA |
| csa.gov.sg | Critical Vulnerabilities in SAP Commerce Cloud and SAP S/4HANA |
Priority History
Initial analysis