CVE-2026-24321 | SAP Commerce Cloud 2211-JDK21/COM_CLOUD 2211/HY_COM 2205 API Endpoint private personal information
A vulnerability was found in SAP Commerce Cloud 2211-JDK21/COM_CLOUD 2211/HY_COM 2205. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component API Endpoint. Performing a manipulation results in exposure of private personal information to an unauthorized actor.
This vulnerability is reported as CVE-2026-24321. The attack is possible to be carried out remotely. No exploit exists.
To fix this issue, it is recommended to deploy a patch.