CVE Vulnerabilities

CVE-2026-23684

Race Condition within a Thread

Published: Feb 10, 2026 | Modified: Feb 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

Weakness

If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.

Affected Software

NameVendorStart VersionEnd Version
Commerce_cloudSap2205 (including)2205 (including)
Commerce_cloudSap2211 (including)2211 (including)

Potential Mitigations

References