CVE-2026-23684CWE-366

Race condition vulnerability in SAP Commerce Cloud

Medium · published February 10, 2026

CVSS v3.1
5.9
EPSS
0%
Percentile
5.9
In the wild
Unconfirmed
What it is

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00164 · 5.9th percentile
Weakness
CWE-366 · Race Condition within a Thread
Published
2026-02-10T03:02Z
EPSS history
Timeline
  • 10 FEB 03:02Z
    Race condition vulnerability in SAP Commerce Cloud
    cvelistv5