CVE-2026-24321Disclosure(sap / commerce_cloud)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-359

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commerce_cloud

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
commerce_cloud

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-10: 1Mentions · 2026-09-10: 1Technical Details · 2026-02-10: 1Technical Details · 2026-09-10: 102-1009-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Home Assistant ESPHome Add-on, Authentication Bypass via Network Binding, #CVE-2026-24321 (Critical) -DC-Sep2026-2314 https://dailycve.com/home-assistant-esphome-add-on-authentication-bypass-via-network-binding-cve-2026-24321-critical-dc-sep2026-2314/

    Post summary

    The text announces a critical authentication bypass vulnerability (CVE‑2026‑24321) in the Home Assistant ESPHome add‑on, indicating an authentication flaw via network binding, but does not provide PoC, exploit, or patch details.

    0001054
    237 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24321 Unauthenticated Information Disclosure in SAP Commerce Cl... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24321 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A new unauthenticated information disclosure vulnerability (CVE-2026-24321) in SAP Commerce has been announced, but no PoC, exploit, active exploitation, or patch details are provided.

    0001070
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsapcommerce_cloud2205--
Appsapcommerce_cloud2211--

Explore more