Advisory
On 09.06.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Commerce Cloud.
SAP Note 3748262 addresses "3748262 - [CVE-2026-22732] Potential Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub" to prevent weak security function with a hot news risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAP Commerce Cloud and SAP Data Hub use a vulnerable version of Spring Security that fails to write HTTP security response headers on certain request paths, allowing an unauthenticated attacker to exploit the missing headers, resulting in unauthorized access to sensitive data and unauthorized modification of data.
Solution
Spring Security has been upgraded to a version not affected by CVE-2026-22732.
The advisory is valid for
