VYPR
Critical severity9.6NVD Advisory· Published May 12, 2026· Updated May 15, 2026

CVE-2026-34263

CVE-2026-34263

Description

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

4