Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-76969: SAP CAP multitenant library can expose credentials

CVE-2026-76969 · published 18 days ago
Summary

The @sap/cds-mtxs library used in SAP Cloud Application Programming Model (CAP) multitenant apps does not check certain requests properly. This lets anyone on the internet send a crafted request and retrieve system credentials, which could be used to change or delete a tenant's data. Update the library to the latest version or apply the vendor's patch to stop the issue.

What to do
  • Update sap cds-mtxs to version 4.0.3.
  • Update sap cds-mtxs to version 3.9.7.
  • Update sap cds-mtxs to version 2.7.7.
  • Update sap cds-mtxs to version 1.18.4.
Affected software
Ecosystem VendorProductAffected versions
– sap_se sap cloud application programming model (cap) @sap/cds-mtxs <=1.18.3
npm sap cds-mtxs >= 4.0.1, < 4.0.3
>= 3.0.1, < 3.9.7
>= 2.0.2, < 2.7.7
< 1.18.4
Fix: upgrade to 4.0.3
Original advisory text
@sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.
Severity
9.4 Critical
CVSS 3.1: 9.4 (MITRE)
Exploitation
EPSS <1%
Type
CWE-522Insufficiently Protected Credentials
Timeline
Published8 Sep 2026
Updated25 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-76969 · MITRE
Track software like this
Free during beta