DIRAS TAKE
Urgent: this is a remote, unauthenticated flaw that can expose credentials and let attackers alter or delete tenant data; prioritize mitigation for internet-facing CAP services immediately. The highest-risk fact is that no authentication is required to trigger the issue (pre-auth access).
What is CVE-2026-76969?
An unauthenticated attacker can send crafted requests to SAP Cloud Application Programming Model (CAP) components and obtain sensitive credentials, then use them to modify or delete tenant data, impacting integrity and availability. CVE-2026-76969 affects CAP components including @sap/cds-mtxs versions up to 1.18.3 and CAP releases up to 2.7.6, 3.9.6, and 4.0.2. Exploitation requires network access to a vulnerable CAP deployment and no valid account or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Which versions of SAP SAP Cloud Application Programming Model (CAP) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| SAP Cloud Application Programming Model (CAP) | @sap/cds-mtxs <=1.18.3 | |
| SAP Cloud Application Programming Model (CAP) | <=2.7.6 | |
| SAP Cloud Application Programming Model (CAP) | <=3.9.6 | |
| SAP Cloud Application Programming Model (CAP) | <=4.0.2 |
Is CVE-2026-76969 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-76969
- Isolate or restrict network exposure of CAP management and extensibility endpoints until vendor guidance or fixes are applied.
- Disable or limit multitenant extensibility features if possible, per your deployment config and vendor recommendations.
- Harden credential stores and rotate any potentially exposed credentials; review and revoke excessive keys and service accounts.
- Enable detailed logging and monitor for unusual requests and tenant-data modification activity; follow vendor guidance when it is published.
Frequently asked questions
Is CVE-2026-76969 being actively exploited?
There are no public reports of exploitation of CVE-2026-76969 as of 2026-09-30.
Which SAP Cloud Application Programming Model versions are affected by CVE-2026-76969?
SAP CAP is affected where @sap/cds-mtxs is at or below 1.18.3 and CAP releases are at or below 2.7.6, 3.9.6, and 4.0.2, according to the available affected lists.
Is there a patch for CVE-2026-76969?
No fixed versions are listed in the available facts; follow vendor guidance for patches or mitigations when they are released.
Does CVE-2026-76969 require authentication?
No; the vulnerability can be triggered by an unauthenticated actor sending specially crafted requests to vulnerable SAP CAP components.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76969
- cve.org/CVERecord?id=CVE-2026-76969
- me.sap.com/notes/3798315
- url.sap/sapsecuritypatchday
- All SAP CVEs on CVE Radar
- CVEs published in September 2026