CVE-2026-76969Critical· 9.4▾ Midnight@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@sap/cds-mtxs >= 4.0.1, < 4.0.3@sap/cds-mtxs >= 3.0.1, < 3.9.7@sap/cds-mtxs >= 2.0.2, < 2.7.7@sap/cds-mtxs < 1.18.4Patched in:
@sap/cds-mtxs 4.0.3@sap/cds-mtxs 3.9.7@sap/cds-mtxs 2.7.7@sap/cds-mtxs 1.18.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76977Medium· 4.3SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist
CVE-2026-76971Medium· 6.5Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests
CVE-2026-76968Medium· 6.5SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state…
CVE-2026-76967High· 7.8SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup
CVE-2026-76963Medium· 4.3Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information
CVE-2026-76962Medium· 4.3SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality