Medium severity5.3NVD Advisory· Published Nov 10, 2020· Updated Jun 17, 2026
CVE-2020-26809
CVE-2020-26809
Description
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:1811:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:1905:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:2005:*:*:*:*:*:*:*
- (no CPE)range: 1808,1811,1905,2005
- SAP SE/SAP Commerce Cloudv5Range: < 1808
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2021/Jun/27nvdExploitMailing ListThird Party Advisory
- packetstormsecurity.com/files/163146/SAP-Hybris-eCommerce-Information-Disclosure.htmlnvdThird Party Advisory
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.