EUVD Vulnerability Catalog

EUVD-2026-72586

Severity: CRITICAL Base Score: 9.4 CVSS Version: 3.1

Vulnerability Description

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality Impact (C): Low
Integrity Impact (I): High
Availability Impact (A): High

Affected Vendors & Systems

Vendor SAP_SE

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

sap

EPSS Probability

0

Known Aliases
GHSA-955m-rr6m-2f9v CVE-2026-76969
Published On

2026-09-08

Last Updated

2026-09-08