CVE Explorer
CVE-2026-23684
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SAP Commerce Cloud","vendor":"SAP_SE","versions":[{"status":"affected","version":"HY_COM 2205"},{"status":"affected","version":"COM_CLOUD 2211"},{"status":"affected","version":"2211-JDK21"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:eb9fb25a54be196850893c9124611ee79e48de88130db676bd5d5ea88a069643 · sha256:ca518c6724b260eb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:eb9fb25a54be196850893c9124611ee79e48de88130db676bd5d5ea88a069643 · sha256:ca518c6724b260eb… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-366","description":"CWE-366: Race Condition within a Thread","lang":"eng","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:eb9fb25a54be196850893c9124611ee79e48de88130db676bd5d5ea88a069643 · sha256:ca518c6724b260eb… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://me.sap.com/notes/3689543"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:eb9fb25a54be196850893c9124611ee79e48de88130db676bd5d5ea88a069643 · sha256:ca518c6724b260eb… · /containers/cna/references/0
{"url":"https://url.sap/sapsecuritypatchday"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:eb9fb25a54be196850893c9124611ee79e48de88130db676bd5d5ea88a069643 · sha256:ca518c6724b260eb… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.