CVE-2026-23684
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.16%
- CWE
- CWE-366
- Published
- 2026-02-10
- Last modified
- 2026-03-12
Affected products
- SAP_SE SAP Commerce Cloud
- SAP_SE SAP Commerce Cloud
- SAP_SE SAP Commerce Cloud
Weakness type
Related vulnerabilities
- CVE-2026-3904 — Calling NSS-backed functions that support caching via nscd may call the...
- CVE-2026-22819 — Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts
- CVE-2025-31115 — XZ has a heap-use-after-free bug in threaded .xz decoder
- CVE-2024-10630 — A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local...
- CVE-2024-2032 — Race Condition Vulnerability in zenml-io/zenml
- CVE-2023-6546 — Kernel: gsm multiplexing race condition leads to privilege escalation
- CVE-2023-39198 — Kernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()
- CVE-2023-4732 — Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.h