CVE-2026-76969
SAP Cloud Application Programming Model credential disclosure allows unauthenticated tenant data replacement or deletion (CVE-2026-76969)
SAP Cloud Application Programming Model (CAP) multitenant applications using @sap/cds-mtxs at or below 1.18.3, 2.7.6, 3.9.6 and 4.0.2 allow unauthenticated credential disclosure leading to tenant data replacement or deletion. Apply SAP Note 3798315.
What happened
The @sap/cds-mtxs npm library does not perform sufficient checks on certain functionality used in multitenant SAP Cloud Application Programming Model (CAP) applications with extensibility enabled. An unauthenticated attacker can send specially crafted requests over the network to obtain sensitive credentials. No user interaction or prior access is required.
SAP rates this as critical with CVSS 3.1 score 9.4 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H). An attacker who obtains the credentials can abuse them to replace or delete tenant data, giving high impact to availability and integrity and partial impact to confidentiality. The source material does not record exploitation in the wild, and the issue has not been publicly disclosed.
Who is affected
The affected product is SAP Cloud Application Programming Model (CAP), specifically the @sap/cds-mtxs npm library. This concerns multitenant CAP applications with extensibility enabled. The affected versions are @sap/cds-mtxs at or below 1.18.3, at or below 2.7.6, at or below 3.9.6, and at or below 4.0.2. If you operate such a multitenant CAP application and depend on this library, review the version in your dependency tree.
What to do now
- Apply SAP Note 3798315, the vendor-provided fix for this issue. The advisory does not list fixed package version numbers, so follow the note's update instructions.
- Until the note is applied, reduce network exposure of affected multitenant CAP applications to trusted users and networks and monitor for unusual access. SAP has not published a workaround for this vulnerability.
How to detect it
SAP has not published specific detection guidance or indicators of compromise for this advisory. Because successful exploitation can replace or delete tenant data, review application and tenant activity logs for unexpected data changes and investigate unusual credential use in multitenant CAP applications.
Beyond the patch
This is a network-reachable, unauthenticated weakness in an SAP development library, so exposure management matters as much as patching. Virtual CISO Services can help identify and reduce exposed SAP application services. Our SAP HANA Security & Cloud Migration practice can review the CAP multitenancy and extensibility configuration itself.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| SAP Cloud Application Programming Model (CAP) | @sap/cds-mtxs <=1.18.3 <=2.7.6 <=3.9.6 <=4.0.2 | No fixed version listed yet |