Advisory
On 09.06.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Commerce Cloud.
SAP Note 3748262 addresses "3748262 - [CVE-2026-22732] Potential Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub" to prevent weak security function with a hot news risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAP Commerce Cloud and SAP Data Hub use a vulnerable version of Spring Security that fails to apply HTTP security response headers on certain request paths, allowing an unauthenticated attacker to exploit the missing headers and gain unauthorized access to sensitive data or perform unauthorized data modification.
Solution
Spring Security has been upgraded to a version that is not affected by CVE-2026-22732.
The advisory is valid for
