CVE-2026-34263
CVSS 9.6 CRITICAL: due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious… EPSS 0.6% (47º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Commerce è il bug più pericoloso qui. Un controllo di autenticazione mancante in un percorso di configurazione cloud consente a un utente non autenticato di caricare una configurazione malevola e raggiungere l’esecuzione arbitraria di codice lato server, quindi la solita supposizione che solo utenti con privilegi possano attivare vulnerabilità lato admin di SAP non regge.
2 fonti · 12 mag
CVSS 9.6 CRITICAL: due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious… EPSS 0.6% (47º percentile).
CVSS 9.6 CRITICAL: sAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. EPSS 0.4% (35º percentile).
SecurityWeek
SAP Patches Critical S/4HANA, Commerce Vulnerabilities
The flaws could allow attackers to inject malicious code, leading to information disclosure and code execution.
originaleBleepingComputer
SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
SAP has released the May 2026 security updates addressing 15 vulnerabilities across multiple products, including two critical flaws in the Commerce Cloud enterprise-grade e-commerce platform and the S/4HANA ERP suite.
originalePart of the PlainSec briefing for 2026-05-13
Every edition of this story: La vulnerabilità di SAP Commerce apre l’esecuzione di codice lato server senza autenticazione