Advisory
On 10.02.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Commerce Cloud.
SAP Note 3689543 addresses "[CVE-2026-23684] Race condition vulnerability in SAP Commerce Cloud" to prevent race condition with a medium risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAP Commerce Cloud allows an unauthenticated attacker to manipulate concurrent add-to-cart requests, potentially resulting in incorrect product values being stored and processed during checkout, leading to unauthorized modification of transactional data.
Solution
The add-to-cart API has been enhanced with a transactional mechanism and optimistic locking properties to prevent concurrency conflicts and ensure consistent cart data.
