---
id: CVE-2026-76969
title: >-
  @sap/cds-mtxs NPM library does not perform sufficient checks on certain
  functionality used in multitenant CAP applications with extensibility enabled
summary: >-
  @sap/cds-mtxs NPM library does not perform sufficient checks on certain
  functionality used in multitenant CAP applications with extensibility enabled.
  An unauthenticated attacker could send specially crafted requests to obtain
  sensitive …
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-522
vendor: SAP_SE
product: SAP Cloud Application Programming Model (CAP)
affected:
  - sap_cloud_application_programming_model_cap @sap/cds-mtxs <=1.18.3
  - sap_cloud_application_programming_model_cap <=2.7.6
  - sap_cloud_application_programming_model_cap <=3.9.6
  - sap_cloud_application_programming_model_cap <=4.0.2
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76969'
references:
  - url: 'https://me.sap.com/notes/3798315'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76969'
  - url: 'https://github.com/advisories/GHSA-955m-rr6m-2f9v'
tags:
  - nvd
  - cve.org
  - ghsa
  - npm
epss: 0.00443
epssPercentile: 0.35832
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T10:04:59.274440Z'
ingestedAt: '2026-09-08T15:33:26.981Z'
aliases:
  - GHSA-955m-rr6m-2f9v
ecosystem: npm
patched:
  - '@sap/cds-mtxs 4.0.3'
  - '@sap/cds-mtxs 3.9.7'
  - '@sap/cds-mtxs 2.7.7'
  - '@sap/cds-mtxs 1.18.4'
---

## Overview

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-76969)

Affected packages:

- `@sap/cds-mtxs >= 4.0.1, < 4.0.3`
- `@sap/cds-mtxs >= 3.0.1, < 3.9.7`
- `@sap/cds-mtxs >= 2.0.2, < 2.7.7`
- `@sap/cds-mtxs < 1.18.4`

Patched in:

- `@sap/cds-mtxs 4.0.3`
- `@sap/cds-mtxs 3.9.7`
- `@sap/cds-mtxs 2.7.7`
- `@sap/cds-mtxs 1.18.4`

Source: https://github.com/advisories/GHSA-955m-rr6m-2f9v
