CVE-2026-76969

9.4

SAP · SAP Cloud Application Programming Model (CAP)

The @sap/cds-mtxs library contains a vulnerability where insufficient checks allow unauthenticated attackers to steal credentials and manipulate tenant data in multitenant CAP applications.

Executive summary

A critical vulnerability in the SAP Cloud Application Programming Model allows unauthenticated remote attackers to compromise sensitive credentials and manipulate tenant data.

Vulnerability

This is a credential protection flaw (CWE-522) within the @sap/cds-mtxs library. An unauthenticated attacker can send crafted requests to exploit extensibility features, leading to unauthorized credential access and subsequent data replacement or deletion.

Business impact

The exploitation of this vulnerability poses a severe risk to business operations, as it directly threatens the integrity and availability of multitenant application data. With a CVSS score of 9.4, the potential for unauthorized data deletion or service disruption is critical, which could result in significant financial loss and a breach of data governance policies.

Remediation

Immediate Action: Review the official SAP Security Note 3798315 to identify the specific patched version for your deployment of the @sap/cds-mtxs library and apply the update immediately.

Proactive Monitoring: Monitor application access logs for unusual requests targeting extensibility endpoints or unauthorized attempts to perform administrative actions on tenant data.

Compensating Controls: Implement strict network ingress controls and utilize a Web Application Firewall to filter malicious traffic patterns that attempt to interact with the vulnerable multitenant extensibility functions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS severity of 9.4 and the ability for unauthenticated actors to access sensitive credentials, this vulnerability must be treated as a high priority. Organizations using the affected SAP CAP libraries should prioritize the verification of their current versions and coordinate with their development teams to apply the vendor-provided patches as soon as they are made available via the SAP support portal.

More SAP CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources